2026 CVE Vulnerabilities
43,311 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48434 | MEDIUM | 6.2 | 0.2% | Aug 11, 2026 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application... |
| CVE-2026-48387 | MEDIUM | 6.2 | 0.2% | Aug 11, 2026 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati... |
| CVE-2026-48386 | HIGH | 7.5 | 0.7% | Aug 11, 2026 | ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure... |
| CVE-2026-48385 | HIGH | 7.7 | 0.8% | Aug 11, 2026 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') ... |
| CVE-2026-48384 | MEDIUM | 4.9 | 0.7% | Aug 11, 2026 | ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-servi... |
| CVE-2026-48376 | MEDIUM | 5.4 | 0.5% | Aug 11, 2026 | is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. ... |
| CVE-2026-48375 | MEDIUM | 6.5 | 0.6% | Aug 11, 2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service... |
| CVE-2026-48362 | CRITICAL | 10 | 2.1% | Aug 11, 2026 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') ... |
| CVE-2026-47922 | MEDIUM | 4.7 | 0.7% | Aug 11, 2026 | CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege... |
| CVE-2026-47704 | HIGH | 7.1 | 0.5% | Aug 11, 2026 | TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can... |
| CVE-2026-47299 | HIGH | 7.2 | 1.0% | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an aut... |
| CVE-2026-47285 | MEDIUM | 6.5 | 0.9% | Aug 11, 2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau... |
| CVE-2026-43606 | HIGH | 8.5 | 0.1% | Aug 11, 2026 | Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local acce... |
| CVE-2026-42976 | HIGH | 7.8 | 0.2% | Aug 11, 2026 | Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges loca... |
| CVE-2026-40375 | MEDIUM | 6.5 | — | Aug 11, 2026 | Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. |
| CVE-2026-39452 | MEDIUM | 6.3 | 0.4% | Aug 11, 2026 | Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applicatio... |
| CVE-2026-35502 | MEDIUM | 4.6 | 0.3% | Aug 11, 2026 | Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Appli... |
| CVE-2026-34635 | HIGH | 8.4 | 0.2% | Aug 11, 2026 | is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low... |
| CVE-2026-34175 | MEDIUM | 5.4 | 0.2% | Aug 11, 2026 | Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User... |
| CVE-2026-32791 | MEDIUM | 5.4 | 0.1% | Aug 11, 2026 | Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring... |
| CVE-2026-32788 | MEDIUM | 5.4 | 0.2% | Aug 11, 2026 | Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring... |
| CVE-2026-32677 | MEDIUM | 5.4 | 0.2% | Aug 11, 2026 | Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an esca... |
| CVE-2026-28757 | MEDIUM | 5.4 | 0.1% | Aug 11, 2026 | Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may... |
| CVE-2026-28729 | LOW | 2.4 | 0.1% | Aug 11, 2026 | Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System softw... |
| CVE-2026-28707 | MEDIUM | 5.4 | 0.1% | Aug 11, 2026 | Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escala... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now