2026 CVE Vulnerabilities
50,939 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47682 | HIGH | 7.1 | 0.3% | Aug 4, 2026 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0... |
| CVE-2026-18810 | HIGH | 7.3 | 0.4% | Aug 4, 2026 | A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard... |
| CVE-2026-18657 | HIGH | 7.8 | 0.2% | Aug 4, 2026 | An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated ac... |
| CVE-2026-18656 | HIGH | 7.8 | 0.2% | Aug 4, 2026 | An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated a... |
| CVE-2026-16793 | HIGH | 8.8 | 0.4% | Aug 4, 2026 | An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo ... |
| CVE-2026-16792 | MEDIUM | 6.1 | 0.1% | Aug 4, 2026 | An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 micr... |
| CVE-2026-16791 | LOW | 3.9 | 0.1% | Aug 4, 2026 | A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could ... |
| CVE-2026-70474 | HIGH | 7.6 | 0.3% | Aug 4, 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow... |
| CVE-2026-70473 | HIGH | 8.3 | — | Aug 4, 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow... |
| CVE-2026-70472 | HIGH | 7.1 | 0.2% | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-... |
| CVE-2026-70471 | HIGH | 7.1 | — | Aug 4, 2026 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow... |
| CVE-2026-69704 | HIGH | 7 | 0.3% | Aug 4, 2026 | Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan... |
| CVE-2026-69703 | CRITICAL | 9.8 | — | Aug 4, 2026 | Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ th... |
| CVE-2026-69702 | HIGH | 7.1 | 0.3% | Aug 4, 2026 | SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a... |
| CVE-2026-68743 | HIGH | 7.1 | 0.1% | Aug 4, 2026 | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length... |
| CVE-2026-66300 | MEDIUM | 5 | 0.2% | Aug 4, 2026 | SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. ... |
| CVE-2026-49435 | CRITICAL | 9.8 | 0.8% | Aug 4, 2026 | Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote att... |
| CVE-2026-47781 | HIGH | 8.4 | 0.1% | Aug 4, 2026 | PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-... |
| CVE-2026-47764 | HIGH | 8.4 | 0.1% | Aug 4, 2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnera... |
| CVE-2026-13229 | HIGH | 7.1 | 0.2% | Aug 4, 2026 | Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning end... |
| CVE-2026-0163 | CRITICAL | 9.8 | — | Aug 4, 2026 | In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem... |
| CVE-2026-70470 | CRITICAL | 9.5 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validat... |
| CVE-2026-69264 | CRITICAL | 9.4 | — | Aug 4, 2026 | Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Pyt... |
| CVE-2026-47763 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm wri... |
| CVE-2026-47623 | HIGH | 8.2 | 0.3% | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A succ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now