2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71555 | MEDIUM | 4.1 | 0.2% | Aug 6, 2026 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS do... |
| CVE-2026-71554 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header ... |
| CVE-2026-71498 | MEDIUM | 5.1 | 0.2% | Aug 6, 2026 | node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final byt... |
| CVE-2026-71497 | MEDIUM | 4.7 | 0.2% | Aug 6, 2026 | jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl... |
| CVE-2026-71478 | MEDIUM | 6.1 | 0.2% | Aug 6, 2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the Attributes... |
| CVE-2026-71447 | MEDIUM | 6.9 | 0.2% | Aug 6, 2026 | AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages... |
| CVE-2026-71446 | MEDIUM | 6.9 | 0.2% | Aug 6, 2026 | AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedde... |
| CVE-2026-71439 | MEDIUM | 5.3 | 0.4% | Aug 6, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.... |
| CVE-2026-71437 | MEDIUM | 6.5 | 0.3% | Aug 6, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.... |
| CVE-2026-71436 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.... |
| CVE-2026-71435 | MEDIUM | 6.1 | 0.2% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automag... |
| CVE-2026-71434 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms... |
| CVE-2026-71433 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin... |
| CVE-2026-71430 | MEDIUM | 6.2 | 0.1% | Aug 6, 2026 | node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function... |
| CVE-2026-71325 | MEDIUM | 4.8 | 0.1% | Aug 6, 2026 | Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25... |
| CVE-2026-70639 | MEDIUM | 6.8 | 0.1% | Aug 6, 2026 | llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper w... |
| CVE-2026-70631 | MEDIUM | 6.8 | 0.1% | Aug 6, 2026 | FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in ... |
| CVE-2026-70630 | MEDIUM | 6.8 | 0.1% | Aug 6, 2026 | FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na... |
| CVE-2026-70629 | MEDIUM | 6.8 | 0.1% | Aug 6, 2026 | FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na... |
| CVE-2026-64677 | MEDIUM | 5.9 | 0.8% | Aug 6, 2026 | Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not ... |
| CVE-2026-64664 | MEDIUM | 4.3 | 0.3% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont... |
| CVE-2026-64663 | MEDIUM | 6.5 | 0.3% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup... |
| CVE-2026-64662 | MEDIUM | 6.5 | 0.3% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont... |
| CVE-2026-64654 | MEDIUM | 5.3 | 0.7% | Aug 6, 2026 | GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed ex... |
| CVE-2026-64653 | MEDIUM | 5.1 | 0.5% | Aug 6, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable pat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now