2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64636 | HIGH | 7.7 | — | Aug 7, 2026 | An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to rea... |
| CVE-2026-19082 | HIGH | 7.5 | — | Aug 7, 2026 | Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count... |
| CVE-2026-71556 | HIGH | 7.1 | — | Aug 7, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree opera... |
| CVE-2026-68772 | HIGH | 8.5 | — | Aug 7, 2026 | ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attacke... |
| CVE-2026-67585 | HIGH | 8.7 | 0.4% | Aug 7, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthent... |
| CVE-2026-20348 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c... |
| CVE-2026-20347 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do... |
| CVE-2026-20346 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c... |
| CVE-2026-20345 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS c... |
| CVE-2026-20339 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a Do... |
| CVE-2026-20338 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi... |
| CVE-2026-20337 | HIGH | 7.5 | 0.4% | Aug 7, 2026 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condi... |
| CVE-2026-19211 | HIGH | 7.3 | 0.3% | Aug 7, 2026 | A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /socia... |
| CVE-2026-17603 | HIGH | 8.7 | — | Aug 7, 2026 | Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the Data... |
| CVE-2026-17601 | HIGH | 8.9 | — | Aug 7, 2026 | A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their ... |
| CVE-2026-17600 | HIGH | 8.7 | — | Aug 7, 2026 | Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio... |
| CVE-2026-17594 | HIGH | 8.2 | — | Aug 7, 2026 | Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in th... |
| CVE-2026-17593 | HIGH | 7.2 | — | Aug 7, 2026 | An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permissi... |
| CVE-2026-14644 | HIGH | 8.6 | — | Aug 7, 2026 | Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with... |
| CVE-2026-18497 | HIGH | 7.1 | 0.2% | Aug 7, 2026 | A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p... |
| CVE-2026-15570 | HIGH | 7.1 | — | Aug 7, 2026 | An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245... |
| CVE-2026-66494 | HIGH | 8.7 | — | Aug 7, 2026 | Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut... |
| CVE-2026-15816 | HIGH | 7.5 | — | Aug 7, 2026 | A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs... |
| CVE-2026-71559 | HIGH | 7.5 | 0.2% | Aug 7, 2026 | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de... |
| CVE-2026-54218 | HIGH | 8.8 | — | Aug 7, 2026 | Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now