2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71321 | HIGH | 7.5 | — | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren... |
| CVE-2026-71320 | HIGH | 8.1 | 0.4% | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject ... |
| CVE-2026-71316 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries ... |
| CVE-2026-67865 | HIGH | 7.5 | — | Aug 5, 2026 | S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denia... |
| CVE-2026-67864 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement ty... |
| CVE-2026-71315 | HIGH | 8.2 | — | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules ... |
| CVE-2026-71314 | HIGH | 7.5 | — | Aug 5, 2026 | Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta... |
| CVE-2026-71312 | HIGH | 8 | 0.3% | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v... |
| CVE-2026-71309 | HIGH | 8.6 | — | Aug 5, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.... |
| CVE-2026-34966 | HIGH | 8.3 | 0.3% | Aug 5, 2026 | Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass... |
| CVE-2026-18411 | HIGH | 8.1 | — | Aug 5, 2026 | The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k... |
| CVE-2026-17583 | HIGH | 8.4 | — | Aug 5, 2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be ed... |
| CVE-2026-70617 | HIGH | 8.6 | 0.2% | Aug 5, 2026 | Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attac... |
| CVE-2026-70616 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl... |
| CVE-2026-69111 | HIGH | 8.7 | 0.6% | Aug 5, 2026 | Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers... |
| CVE-2026-68746 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to... |
| CVE-2026-66881 | HIGH | 8.1 | 0.4% | Aug 5, 2026 | Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with... |
| CVE-2026-66298 | HIGH | 8.8 | 0.2% | Aug 5, 2026 | Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se... |
| CVE-2026-66297 | HIGH | 8 | 1.3% | Aug 5, 2026 | Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l... |
| CVE-2026-55524 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on... |
| CVE-2026-55523 | HIGH | 7.7 | 0.3% | Aug 5, 2026 | PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.w... |
| CVE-2026-55522 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p... |
| CVE-2026-18958 | HIGH | 7.3 | 0.3% | Aug 5, 2026 | A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a... |
| CVE-2026-18953 | HIGH | 8.8 | 0.1% | Aug 5, 2026 | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp... |
| CVE-2026-17556 | HIGH | 8.8 | — | Aug 5, 2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now