2026 CVE Vulnerabilities
50,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59913 | HIGH | 7.8 | 0.1% | Aug 3, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti... |
| CVE-2026-59912 | HIGH | 7.8 | 0.1% | Aug 3, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnera... |
| CVE-2026-38447 | CRITICAL | 9.8 | — | Aug 3, 2026 | osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with ... |
| CVE-2026-38446 | MEDIUM | 6.1 | — | Aug 3, 2026 | A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread e... |
| CVE-2026-38444 | MEDIUM | 6.1 | — | Aug 3, 2026 | osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is... |
| CVE-2026-18616 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of... |
| CVE-2026-18615 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate... |
| CVE-2026-18614 | CRITICAL | 9.8 | 2.0% | Aug 3, 2026 | A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file ... |
| CVE-2026-61524 | HIGH | 8.6 | — | Aug 3, 2026 | WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th... |
| CVE-2026-61523 | HIGH | 8.6 | — | Aug 3, 2026 | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated... |
| CVE-2026-40717 | HIGH | 7.8 | 0.1% | Aug 3, 2026 | Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnera... |
| CVE-2026-18613 | CRITICAL | 9.8 | 0.5% | Aug 3, 2026 | A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of t... |
| CVE-2026-18612 | CRITICAL | 9.8 | 2.2% | Aug 3, 2026 | A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/p... |
| CVE-2026-69153 | MEDIUM | 5.3 | 0.4% | Aug 3, 2026 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ... |
| CVE-2026-69152 | HIGH | 7.5 | 0.4% | Aug 3, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3... |
| CVE-2026-69151 | MEDIUM | 6.1 | 0.3% | Aug 3, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-69149 | MEDIUM | 6.1 | 0.3% | Aug 3, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-68945 | MEDIUM | 6.1 | 0.2% | Aug 3, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-68930 | MEDIUM | 6.5 | — | Aug 3, 2026 | Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci... |
| CVE-2026-68869 | — | — | — | Aug 3, 2026 | Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a securit... |
| CVE-2026-67612 | MEDIUM | 4.8 | — | Aug 3, 2026 | OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al... |
| CVE-2026-67611 | HIGH | 8.6 | — | Aug 3, 2026 | OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci... |
| CVE-2026-67610 | HIGH | 8.1 | — | Aug 3, 2026 | OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi... |
| CVE-2026-61372 | HIGH | 7.5 | 0.4% | Aug 3, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Thi... |
| CVE-2026-41453 | HIGH | 8.8 | — | Aug 3, 2026 | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now