2026 CVE Vulnerabilities
50,972 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18682 | LOW | 3.1 | 0.2% | Aug 3, 2026 | A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api... |
| CVE-2026-10849 | HIGH | 7.5 | 0.3% | Aug 3, 2026 | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser... |
| CVE-2026-69246 | HIGH | 7.2 | 0.2% | Aug 3, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and... |
| CVE-2026-69245 | MEDIUM | 6.5 | — | Aug 3, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of ... |
| CVE-2026-69244 | HIGH | 7.1 | 0.3% | Aug 3, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap r... |
| CVE-2026-69243 | MEDIUM | 6.3 | 0.3% | Aug 3, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were v... |
| CVE-2026-69240 | CRITICAL | 9.8 | 0.3% | Aug 3, 2026 | Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl... |
| CVE-2026-67976 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allo... |
| CVE-2026-67972 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data... |
| CVE-2026-66065 | HIGH | 8.4 | 0.3% | Aug 3, 2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ... |
| CVE-2026-52521 | HIGH | 8.1 | 0.1% | Aug 3, 2026 | A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th... |
| CVE-2026-52520 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/... |
| CVE-2026-52102 | CRITICAL | 9.8 | 0.6% | Aug 3, 2026 | An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe... |
| CVE-2026-51775 | CRITICAL | 9.8 | 0.1% | Aug 3, 2026 | SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati... |
| CVE-2026-51190 | CRITICAL | 9.8 | 0.5% | Aug 3, 2026 | The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spaw... |
| CVE-2026-49132 | MEDIUM | 5.4 | 0.1% | Aug 3, 2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec... |
| CVE-2026-49131 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir... |
| CVE-2026-48113 | HIGH | 8.5 | 0.2% | Aug 3, 2026 | Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client... |
| CVE-2026-48063 | CRITICAL | 9.3 | 0.2% | Aug 3, 2026 | Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile... |
| CVE-2026-48061 | MEDIUM | 5.9 | — | Aug 3, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa... |
| CVE-2026-41447 | HIGH | 8.5 | 0.1% | Aug 3, 2026 | FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit... |
| CVE-2026-18738 | MEDIUM | 4.7 | — | Aug 3, 2026 | Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att... |
| CVE-2026-18737 | HIGH | 7.1 | 0.2% | Aug 3, 2026 | Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL... |
| CVE-2026-18736 | MEDIUM | 5.3 | — | Aug 3, 2026 | Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serve... |
| CVE-2026-18733 | HIGH | 8.8 | 0.3% | Aug 3, 2026 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now