2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65668 | HIGH | 8.8 | 0.4% | Aug 7, 2026 | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a netwo... |
| CVE-2026-62918 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing ... |
| CVE-2026-49163 | HIGH | 8.8 | 0.6% | Aug 7, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a... |
| CVE-2026-8325 | HIGH | 7.8 | 0.1% | Aug 6, 2026 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A ma... |
| CVE-2026-7867 | HIGH | 7.8 | 0.2% | Aug 6, 2026 | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec... |
| CVE-2026-7406 | HIGH | 7.8 | 0.1% | Aug 6, 2026 | A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference... |
| CVE-2026-71488 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially craf... |
| CVE-2026-71476 | HIGH | 8.7 | 0.6% | Aug 6, 2026 | Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx sel... |
| CVE-2026-71445 | HIGH | 8.2 | 0.3% | Aug 6, 2026 | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occu... |
| CVE-2026-71327 | HIGH | 7.6 | 0.4% | Aug 6, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes... |
| CVE-2026-71324 | HIGH | 7 | 0.6% | Aug 6, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default H... |
| CVE-2026-70640 | HIGH | 7.3 | 0.2% | Aug 6, 2026 | llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrap... |
| CVE-2026-70638 | HIGH | 8.5 | 0.1% | Aug 6, 2026 | llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where th... |
| CVE-2026-70636 | HIGH | 8.7 | 0.3% | Aug 6, 2026 | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th... |
| CVE-2026-70635 | HIGH | 7.1 | 0.3% | Aug 6, 2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica... |
| CVE-2026-70634 | HIGH | 8.1 | 0.4% | Aug 6, 2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression revers... |
| CVE-2026-70633 | HIGH | 7.1 | 0.4% | Aug 6, 2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres... |
| CVE-2026-70632 | HIGH | 8.5 | 0.2% | Aug 6, 2026 | FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native G... |
| CVE-2026-70628 | HIGH | 8.5 | 0.1% | Aug 6, 2026 | FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtit... |
| CVE-2026-70559 | HIGH | 8.7 | 0.3% | Aug 6, 2026 | Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t... |
| CVE-2026-70557 | HIGH | 7.1 | 0.3% | Aug 6, 2026 | diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of ... |
| CVE-2026-67687 | HIGH | 8.8 | 0.3% | Aug 6, 2026 | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol... |
| CVE-2026-67621 | HIGH | 7.6 | 0.2% | Aug 6, 2026 | Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf... |
| CVE-2026-67434 | HIGH | 7.3 | 0.7% | Aug 6, 2026 | PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.... |
| CVE-2026-67422 | HIGH | 7.5 | 0.6% | Aug 6, 2026 | pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now