2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73492 | LOW | 2.3 | 0.2% | Aug 12, 2026 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri... |
| CVE-2026-73491 | LOW | 2.3 | 0.2% | Aug 12, 2026 | Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri... |
| CVE-2026-73427 | LOW | 2.1 | 0.3% | Aug 12, 2026 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cro... |
| CVE-2026-73425 | LOW | 3.7 | 0.2% | Aug 12, 2026 | Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remo... |
| CVE-2026-18096 | LOW | 3.3 | 0.1% | Aug 12, 2026 | IBM Db2 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to cause a denial ... |
| CVE-2026-11937 | LOW | 3.1 | 0.2% | Aug 12, 2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident... |
| CVE-2026-65926 | LOW | 3.1 | 0.2% | Aug 12, 2026 | An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release B... |
| CVE-2026-49262 | LOW | 3 | 0.1% | Aug 12, 2026 | In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is ... |
| CVE-2026-70467 | LOW | 3.8 | 0.2% | Aug 12, 2026 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM... |
| CVE-2026-18044 | LOW | 3.7 | 0.1% | Aug 12, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use... |
| CVE-2026-64951 | LOW | 3.5 | 0.2% | Aug 12, 2026 | A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic... |
| CVE-2026-73283 | LOW | 2.5 | 0.1% | Aug 11, 2026 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar... |
| CVE-2026-73281 | LOW | 3.5 | 0.2% | Aug 11, 2026 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi... |
| CVE-2026-65655 | LOW | 2.3 | 0.3% | Aug 11, 2026 | When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to ... |
| CVE-2026-73087 | LOW | 2.3 | 0.3% | Aug 11, 2026 | Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal... |
| CVE-2026-28729 | LOW | 2.4 | 0.1% | Aug 11, 2026 | Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System softw... |
| CVE-2026-25194 | LOW | 1.8 | 0.2% | Aug 11, 2026 | Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adve... |
| CVE-2026-73071 | LOW | 3.3 | 0.1% | Aug 11, 2026 | Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta... |
| CVE-2026-11734 | LOW | 2.7 | 0.3% | Aug 11, 2026 | A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de... |
| CVE-2026-73157 | LOW | 2.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi... |
| CVE-2026-11985 | LOW | 3.6 | 0.1% | Aug 11, 2026 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to... |
| CVE-2026-66774 | LOW | 3.7 | 0.2% | Aug 11, 2026 | SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this ... |
| CVE-2026-58245 | LOW | 3.8 | 0.2% | Aug 11, 2026 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th... |
| CVE-2026-58239 | LOW | 3.7 | 0.2% | Aug 11, 2026 | SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send ... |
| CVE-2026-44762 | LOW | 3.7 | 0.1% | Aug 11, 2026 | SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now