2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18531 | MEDIUM | 5.3 | 0.4% | Aug 5, 2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use ... |
| CVE-2026-15656 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook... |
| CVE-2026-12762 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti... |
| CVE-2026-16100 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error... |
| CVE-2026-16071 | MEDIUM | 5.4 | 0.2% | Aug 5, 2026 | A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external direc... |
| CVE-2026-7456 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2026-71293 | MEDIUM | 6.2 | 0.2% | Aug 5, 2026 | Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case f... |
| CVE-2026-71286 | MEDIUM | 6.1 | 0.2% | Aug 5, 2026 | The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property... |
| CVE-2026-71283 | MEDIUM | 4.9 | 0.3% | Aug 5, 2026 | Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile... |
| CVE-2026-71282 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol... |
| CVE-2026-71275 | MEDIUM | 5.4 | — | Aug 5, 2026 | OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r... |
| CVE-2026-71273 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w... |
| CVE-2026-71260 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho... |
| CVE-2026-71227 | MEDIUM | 5.1 | 0.1% | Aug 5, 2026 | A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO... |
| CVE-2026-71225 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat... |
| CVE-2026-0516 | MEDIUM | 6.5 | — | Aug 5, 2026 | A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to... |
| CVE-2026-71251 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download... |
| CVE-2026-71250 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex... |
| CVE-2026-71249 | MEDIUM | 6.1 | 0.2% | Aug 5, 2026 | 299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, f... |
| CVE-2026-71247 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t... |
| CVE-2026-71246 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s... |
| CVE-2026-71244 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r... |
| CVE-2026-71240 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta... |
| CVE-2026-14574 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec... |
| CVE-2026-14304 | MEDIUM | 5.5 | 0.1% | Aug 5, 2026 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now