2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-51144 | MEDIUM | 6.1 | 0.2% | Aug 4, 2026 | Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker ... |
| CVE-2026-18816 | MEDIUM | 5 | 0.3% | Aug 4, 2026 | A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file... |
| CVE-2026-70588 | MEDIUM | 5 | 0.3% | Aug 4, 2026 | Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin fail... |
| CVE-2026-70493 | MEDIUM | 6.5 | 0.3% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built... |
| CVE-2026-70491 | MEDIUM | 6.5 | 0.3% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap... |
| CVE-2026-70490 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the termi... |
| CVE-2026-70489 | MEDIUM | 6.5 | 0.3% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio... |
| CVE-2026-70488 | MEDIUM | 4.3 | 0.2% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync ... |
| CVE-2026-70487 | MEDIUM | 5.3 | 0.3% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di... |
| CVE-2026-54020 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolv... |
| CVE-2026-70484 | MEDIUM | 4.3 | 0.3% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac... |
| CVE-2026-70481 | MEDIUM | 5.4 | 0.3% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the stand... |
| CVE-2026-70480 | MEDIUM | 4.1 | 0.2% | Aug 4, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open Web... |
| CVE-2026-48154 | MEDIUM | 5.9 | 0.2% | Aug 4, 2026 | GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri... |
| CVE-2026-68743 | MEDIUM | 5.5 | — | Aug 4, 2026 | A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length... |
| CVE-2026-66300 | MEDIUM | 5 | — | Aug 4, 2026 | SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. ... |
| CVE-2026-47763 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm wri... |
| CVE-2026-47622 | MEDIUM | 5.3 | 0.2% | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con... |
| CVE-2026-47621 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing... |
| CVE-2026-47620 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing... |
| CVE-2026-47487 | MEDIUM | 4.4 | — | Aug 4, 2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repos... |
| CVE-2026-64630 | MEDIUM | 5.3 | — | Aug 4, 2026 | A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link. |
| CVE-2026-48121 | MEDIUM | 6.7 | — | Aug 4, 2026 | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for sto... |
| CVE-2026-18785 | MEDIUM | 5.3 | 0.1% | Aug 4, 2026 | A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli... |
| CVE-2026-18784 | MEDIUM | 5.3 | 0.1% | Aug 4, 2026 | A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now