2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19036 | HIGH | 7.3 | 2.5% | Aug 6, 2026 | A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp... |
| CVE-2026-68481 | HIGH | 7.5 | — | Aug 6, 2026 | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec... |
| CVE-2026-57818 | HIGH | 8.1 | — | Aug 6, 2026 | A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via c... |
| CVE-2026-19035 | HIGH | 7.3 | 2.5% | Aug 6, 2026 | A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of ... |
| CVE-2026-65432 | HIGH | 7.5 | — | Aug 6, 2026 | Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. Ho... |
| CVE-2026-64958 | HIGH | 7.5 | — | Aug 6, 2026 | An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF... |
| CVE-2026-57819 | HIGH | 7.5 | — | Aug 6, 2026 | Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" co... |
| CVE-2026-57817 | HIGH | 8.1 | — | Aug 6, 2026 | The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in th... |
| CVE-2026-54225 | HIGH | 7.5 | — | Aug 6, 2026 | Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.... |
| CVE-2026-19034 | HIGH | 7.3 | 2.5% | Aug 6, 2026 | A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_s... |
| CVE-2026-55978 | HIGH | 8.4 | — | Aug 6, 2026 | An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an ... |
| CVE-2026-64601 | HIGH | 7.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant us... |
| CVE-2026-64599 | HIGH | 7.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_cry... |
| CVE-2026-64598 | HIGH | 8.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc()... |
| CVE-2026-64588 | HIGH | 7.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakl... |
| CVE-2026-64587 | HIGH | 7 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before... |
| CVE-2026-64586 | HIGH | 8.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device remo... |
| CVE-2026-64585 | HIGH | 7.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing net... |
| CVE-2026-64584 | HIGH | 7.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before ... |
| CVE-2026-64583 | HIGH | 7.8 | 0.2% | Aug 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake... |
| CVE-2026-19021 | HIGH | 7.3 | 0.3% | Aug 6, 2026 | A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by thi... |
| CVE-2026-19010 | HIGH | 7.3 | 0.4% | Aug 6, 2026 | A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag... |
| CVE-2026-19009 | HIGH | 7.3 | 0.4% | Aug 6, 2026 | A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core... |
| CVE-2026-18649 | HIGH | 7.5 | 0.6% | Aug 6, 2026 | A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements d... |
| CVE-2026-18597 | HIGH | 8.5 | — | Aug 6, 2026 | The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now