2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18997 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBg... |
| CVE-2026-18996 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function P... |
| CVE-2026-18995 | MEDIUM | 4.3 | 0.3% | Aug 6, 2026 | A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f... |
| CVE-2026-18993 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functiona... |
| CVE-2026-18992 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of ... |
| CVE-2026-18909 | MEDIUM | 5.6 | 0.1% | Aug 6, 2026 | A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and... |
| CVE-2026-18980 | MEDIUM | 6.3 | 1.3% | Aug 6, 2026 | A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the fi... |
| CVE-2026-18976 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions... |
| CVE-2026-18974 | MEDIUM | 5.5 | 0.3% | Aug 6, 2026 | A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the... |
| CVE-2026-19028 | MEDIUM | 6.8 | 0.1% | Aug 6, 2026 | H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the ... |
| CVE-2026-19027 | MEDIUM | 6.9 | 0.1% | Aug 6, 2026 | The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H... |
| CVE-2026-18968 | MEDIUM | 4.3 | 0.3% | Aug 6, 2026 | A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue... |
| CVE-2026-19026 | MEDIUM | 6.8 | 0.1% | Aug 5, 2026 | H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating th... |
| CVE-2026-19025 | MEDIUM | 6.8 | 0.1% | Aug 5, 2026 | H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout d... |
| CVE-2026-19023 | MEDIUM | 6.8 | 0.1% | Aug 5, 2026 | Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers... |
| CVE-2026-71318 | MEDIUM | 4.8 | 0.2% | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply ... |
| CVE-2026-71313 | MEDIUM | 6.9 | 0.3% | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51... |
| CVE-2026-71311 | MEDIUM | 6.4 | 0.2% | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-71310 | MEDIUM | 5.9 | — | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1... |
| CVE-2026-18959 | MEDIUM | 5.4 | 0.4% | Aug 5, 2026 | A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des... |
| CVE-2026-15996 | MEDIUM | 6.6 | 0.4% | Aug 5, 2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to... |
| CVE-2026-70618 | MEDIUM | 5.3 | — | Aug 5, 2026 | Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user ... |
| CVE-2026-66885 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b... |
| CVE-2026-21766 | MEDIUM | 5.4 | — | Aug 5, 2026 | The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. ... |
| CVE-2026-18954 | MEDIUM | 5.7 | 0.1% | Aug 5, 2026 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now