2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66832 | MEDIUM | 6.9 | — | Aug 11, 2026 | When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app... |
| CVE-2026-66148 | MEDIUM | 6.3 | — | Aug 11, 2026 | An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.10... |
| CVE-2026-63134 | MEDIUM | 5.4 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction w... |
| CVE-2026-63133 | MEDIUM | 6.5 | — | Aug 11, 2026 | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives... |
| CVE-2026-48762 | MEDIUM | 5.4 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a u... |
| CVE-2026-29035 | MEDIUM | 6.5 | — | Aug 11, 2026 | CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that... |
| CVE-2026-19579 | MEDIUM | 5.4 | — | Aug 11, 2026 | Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request ... |
| CVE-2026-19550 | MEDIUM | 4.3 | — | Aug 11, 2026 | A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rath... |
| CVE-2026-73282 | MEDIUM | 4.8 | — | Aug 11, 2026 | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat... |
| CVE-2026-73244 | MEDIUM | 5.3 | — | Aug 11, 2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li... |
| CVE-2026-73243 | MEDIUM | 5.8 | — | Aug 11, 2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add... |
| CVE-2026-73235 | MEDIUM | 6.1 | — | Aug 11, 2026 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constru... |
| CVE-2026-73230 | MEDIUM | 5.9 | — | Aug 11, 2026 | Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version... |
| CVE-2026-73229 | MEDIUM | 4.3 | — | Aug 11, 2026 | Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's... |
| CVE-2026-73036 | MEDIUM | 4.6 | — | Aug 11, 2026 | Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt... |
| CVE-2026-71845 | MEDIUM | 6.3 | 0.2% | Aug 11, 2026 | A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes... |
| CVE-2026-71475 | MEDIUM | 5 | — | Aug 11, 2026 | A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data ... |
| CVE-2026-71474 | MEDIUM | 6.3 | — | Aug 11, 2026 | A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, whic... |
| CVE-2026-71468 | MEDIUM | 5.3 | — | Aug 11, 2026 | A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly ... |
| CVE-2026-70339 | MEDIUM | 5.4 | — | Aug 11, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-66146 | MEDIUM | 6.1 | — | Aug 11, 2026 | Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions ... |
| CVE-2026-73228 | MEDIUM | 5.3 | — | Aug 11, 2026 | Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing ... |
| CVE-2026-73221 | MEDIUM | 5.3 | — | Aug 11, 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user... |
| CVE-2026-69117 | MEDIUM | 6.5 | — | Aug 11, 2026 | NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only... |
| CVE-2026-18709 | MEDIUM | 6.4 | — | Aug 11, 2026 | An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now