2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18775 | MEDIUM | 6.3 | 0.3% | Aug 4, 2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browse... |
| CVE-2026-18774 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file ag... |
| CVE-2026-15920 | MEDIUM | 6.1 | 0.3% | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(... |
| CVE-2026-15830 | MEDIUM | 6.9 | 0.5% | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome... |
| CVE-2026-15337 | MEDIUM | 6.9 | 0.5% | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()... |
| CVE-2026-24078 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. |
| CVE-2026-24077 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel... |
| CVE-2026-24076 | MEDIUM | 6.7 | 0.1% | Aug 4, 2026 | Memory Corruption when processing registry values with incorrect types using a direct query method. |
| CVE-2026-18773 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_... |
| CVE-2026-10032 | MEDIUM | 6.1 | 0.2% | Aug 4, 2026 | The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U... |
| CVE-2026-67618 | MEDIUM | 6.5 | — | Aug 4, 2026 | marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat... |
| CVE-2026-67196 | MEDIUM | 5.4 | 0.1% | Aug 4, 2026 | Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in... |
| CVE-2026-18766 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect... |
| CVE-2026-18401 | MEDIUM | 6.9 | — | Aug 4, 2026 | The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in S... |
| CVE-2026-11368 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning chann... |
| CVE-2026-70368 | MEDIUM | 6.5 | 0.4% | Aug 4, 2026 | A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m... |
| CVE-2026-70367 | MEDIUM | 5.4 | 0.2% | Aug 4, 2026 | A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr... |
| CVE-2026-14337 | MEDIUM | 4.6 | — | Aug 4, 2026 | Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use... |
| CVE-2026-63248 | MEDIUM | 6.5 | 0.2% | Aug 4, 2026 | In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an... |
| CVE-2026-18809 | MEDIUM | 6.5 | — | Aug 4, 2026 | Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153... |
| CVE-2026-66883 | MEDIUM | 6.3 | — | Aug 4, 2026 | Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu... |
| CVE-2026-18772 | MEDIUM | 6.5 | 0.1% | Aug 4, 2026 | Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data ... |
| CVE-2026-14465 | MEDIUM | 6.5 | — | Aug 4, 2026 | Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ... |
| CVE-2026-14219 | MEDIUM | 5.4 | — | Aug 4, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUM... |
| CVE-2026-14202 | MEDIUM | 5.3 | — | Aug 4, 2026 | Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now