2026 CVE Vulnerabilities
50,000 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67866 | HIGH | 7.5 | — | Aug 5, 2026 | Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Lock... |
| CVE-2026-67863 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when ... |
| CVE-2026-19026 | MEDIUM | 6.8 | 0.1% | Aug 5, 2026 | H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating th... |
| CVE-2026-19025 | MEDIUM | 6.8 | 0.1% | Aug 5, 2026 | H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout d... |
| CVE-2026-19024 | HIGH | 8.2 | 0.1% | Aug 5, 2026 | NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a d... |
| CVE-2026-19023 | MEDIUM | 6.8 | 0.1% | Aug 5, 2026 | Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers... |
| CVE-2026-71321 | HIGH | 7.5 | — | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren... |
| CVE-2026-71320 | HIGH | 8.1 | 0.4% | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject ... |
| CVE-2026-71319 | CRITICAL | 9.6 | 0.3% | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) expos... |
| CVE-2026-71318 | MEDIUM | 4.8 | 0.2% | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply ... |
| CVE-2026-71316 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries ... |
| CVE-2026-67865 | HIGH | 7.5 | — | Aug 5, 2026 | S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denia... |
| CVE-2026-67864 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement ty... |
| CVE-2026-71315 | HIGH | 8.2 | — | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules ... |
| CVE-2026-71314 | HIGH | 7.5 | — | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta... |
| CVE-2026-71313 | MEDIUM | 6.9 | 0.3% | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51... |
| CVE-2026-71312 | HIGH | 8 | 0.3% | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v... |
| CVE-2026-71311 | MEDIUM | 6.4 | 0.2% | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-71310 | MEDIUM | 5.9 | — | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-71309 | HIGH | 8.6 | — | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.... |
| CVE-2026-34966 | HIGH | 8.3 | 0.3% | Aug 5, 2026 | Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass... |
| CVE-2026-18959 | MEDIUM | 5.4 | 0.4% | Aug 5, 2026 | A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des... |
| CVE-2026-18839 | LOW | 2.2 | 0.1% | Aug 5, 2026 | An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal ... |
| CVE-2026-18411 | HIGH | 8.1 | — | Aug 5, 2026 | The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k... |
| CVE-2026-17583 | HIGH | 8.4 | — | Aug 5, 2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be ed... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now