2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10128 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbit... |
| CVE-2026-7646 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other u... |
| CVE-2026-70607 | MEDIUM | 5.3 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,... |
| CVE-2026-20311 | MEDIUM | 6.3 | 0.2% | Aug 5, 2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta... |
| CVE-2026-20308 | MEDIUM | 4.3 | 0.3% | Aug 5, 2026 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta... |
| CVE-2026-20294 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem... |
| CVE-2026-20289 | MEDIUM | 5.7 | 0.2% | Aug 5, 2026 | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privilege... |
| CVE-2026-20288 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nb... |
| CVE-2026-20198 | MEDIUM | 4.8 | 0.2% | Aug 5, 2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an aut... |
| CVE-2026-20028 | MEDIUM | 5 | 0.3% | Aug 5, 2026 | A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker... |
| CVE-2026-18927 | MEDIUM | 6.3 | 0.2% | Aug 5, 2026 | A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d4... |
| CVE-2026-14587 | MEDIUM | 5.5 | — | Aug 5, 2026 | Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask... |
| CVE-2026-70606 | MEDIUM | 5.9 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6... |
| CVE-2026-70605 | MEDIUM | 5.9 | 0.2% | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,... |
| CVE-2026-70603 | MEDIUM | 6 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6,... |
| CVE-2026-70602 | MEDIUM | 6.6 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,... |
| CVE-2026-70599 | MEDIUM | 5.9 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,... |
| CVE-2026-70597 | MEDIUM | 6.3 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,... |
| CVE-2026-70596 | MEDIUM | 4.3 | — | Aug 5, 2026 | Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user ... |
| CVE-2026-70595 | MEDIUM | 4 | 0.2% | Aug 5, 2026 | Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s... |
| CVE-2026-53992 | MEDIUM | 6.1 | — | Aug 5, 2026 | ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remot... |
| CVE-2026-50749 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica... |
| CVE-2026-49331 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for... |
| CVE-2026-48912 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ... |
| CVE-2026-39924 | MEDIUM | 6.8 | — | Aug 5, 2026 | Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now