2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73222 | HIGH | 8.8 | — | Aug 11, 2026 | Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio ... |
| CVE-2026-72742 | HIGH | 8.6 | — | Aug 11, 2026 | DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke... |
| CVE-2026-69119 | HIGH | 8.3 | — | Aug 11, 2026 | Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any aut... |
| CVE-2026-69115 | HIGH | 7.1 | — | Aug 11, 2026 | OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o... |
| CVE-2026-48809 | HIGH | 7.5 | — | Aug 11, 2026 | python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw... |
| CVE-2026-48802 | HIGH | 7.5 | — | Aug 11, 2026 | python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta... |
| CVE-2026-18712 | HIGH | 8.1 | — | Aug 11, 2026 | An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg... |
| CVE-2026-18711 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to ... |
| CVE-2026-18706 | HIGH | 7.5 | — | Aug 11, 2026 | An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation ... |
| CVE-2026-18705 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view ... |
| CVE-2026-18704 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor... |
| CVE-2026-18701 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server ... |
| CVE-2026-18697 | HIGH | 8.7 | — | Aug 11, 2026 | An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce... |
| CVE-2026-18696 | HIGH | 7 | — | Aug 11, 2026 | An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to ... |
| CVE-2026-18695 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could... |
| CVE-2026-18694 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus... |
| CVE-2026-18693 | HIGH | 7.6 | — | Aug 11, 2026 | An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges ... |
| CVE-2026-18692 | HIGH | 8.8 | — | Aug 11, 2026 | An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil... |
| CVE-2026-18690 | HIGH | 8.1 | — | Aug 11, 2026 | An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag... |
| CVE-2026-18688 | HIGH | 7.1 | — | Aug 11, 2026 | An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory ... |
| CVE-2026-18687 | HIGH | 7.1 | — | Aug 11, 2026 | MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para... |
| CVE-2026-15426 | HIGH | 8.8 | — | Aug 11, 2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v... |
| CVE-2026-73218 | HIGH | 7.7 | — | Aug 11, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in A... |
| CVE-2026-73217 | HIGH | 7.7 | — | Aug 11, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in A... |
| CVE-2026-73215 | HIGH | 7.1 | — | Aug 11, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now