2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65400 | HIGH | 7.1 | 0.3% | Aug 6, 2026 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS... |
| CVE-2026-64665 | HIGH | 8.1 | 0.3% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was ... |
| CVE-2026-63725 | HIGH | 8.6 | 0.3% | Aug 6, 2026 | sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta... |
| CVE-2026-63637 | HIGH | 8.6 | 0.2% | Aug 6, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.... |
| CVE-2026-62857 | HIGH | 8.8 | 0.2% | Aug 6, 2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the... |
| CVE-2026-5856 | HIGH | 7.1 | 0.3% | Aug 6, 2026 | Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack... |
| CVE-2026-5855 | HIGH | 8.7 | 0.5% | Aug 6, 2026 | Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer lengt... |
| CVE-2026-48084 | HIGH | 7.4 | 0.4% | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions pri... |
| CVE-2026-48081 | HIGH | 8.1 | 0.1% | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver... |
| CVE-2026-48080 | HIGH | 8 | 0.3% | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver... |
| CVE-2026-48079 | HIGH | 7.4 | 0.4% | Aug 6, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver... |
| CVE-2026-48054 | HIGH | 8.8 | 0.5% | Aug 6, 2026 | OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin ... |
| CVE-2026-47765 | HIGH | 7.1 | 0.4% | Aug 6, 2026 | Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints ... |
| CVE-2026-47194 | HIGH | 8.6 | 0.2% | Aug 6, 2026 | Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation c... |
| CVE-2026-45414 | HIGH | 8.5 | 0.3% | Aug 6, 2026 | Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API auth... |
| CVE-2026-45378 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3... |
| CVE-2026-43628 | HIGH | 8.5 | 0.2% | Aug 6, 2026 | llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sample... |
| CVE-2026-43627 | HIGH | 8.5 | 0.1% | Aug 6, 2026 | llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where ... |
| CVE-2026-3415 | HIGH | 8.7 | 0.3% | Aug 6, 2026 | The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validatio... |
| CVE-2026-1289 | HIGH | 7.8 | 0.1% | Aug 6, 2026 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A maliciou... |
| CVE-2026-19177 | HIGH | 8.3 | 0.4% | Aug 6, 2026 | Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who ... |
| CVE-2026-19176 | HIGH | 7.5 | 0.4% | Aug 6, 2026 | Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the render... |
| CVE-2026-19174 | HIGH | 8.8 | 0.4% | Aug 6, 2026 | Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code insi... |
| CVE-2026-19173 | HIGH | 8.3 | 0.2% | Aug 6, 2026 | Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the r... |
| CVE-2026-19172 | HIGH | 8.3 | 0.3% | Aug 6, 2026 | Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the rende... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now