2026 CVE Vulnerabilities
43,311 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11733 | LOW | 1.1 | — | Aug 11, 2026 | A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the ... |
| CVE-2026-73067 | MEDIUM | 6.7 | — | Aug 11, 2026 | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init ca... |
| CVE-2026-73066 | MEDIUM | 6.8 | — | Aug 11, 2026 | Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse... |
| CVE-2026-72925 | MEDIUM | 6.1 | — | Aug 11, 2026 | SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi... |
| CVE-2026-72922 | HIGH | 8.2 | — | Aug 11, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-72921 | HIGH | 8.1 | — | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth... |
| CVE-2026-72920 | CRITICAL | 9.8 | — | Aug 11, 2026 | SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s... |
| CVE-2026-47702 | CRITICAL | 9.1 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the bu... |
| CVE-2026-18860 | HIGH | 8.7 | — | Aug 11, 2026 | Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr... |
| CVE-2026-18636 | MEDIUM | 6.8 | — | Aug 11, 2026 | The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr... |
| CVE-2026-18635 | HIGH | 7.2 | 0.3% | Aug 11, 2026 | Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able ... |
| CVE-2026-18129 | HIGH | 8.1 | — | Aug 11, 2026 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a ... |
| CVE-2026-18127 | HIGH | 7.7 | — | Aug 11, 2026 | External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica... |
| CVE-2026-18125 | HIGH | 7.5 | — | Aug 11, 2026 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated at... |
| CVE-2026-17535 | MEDIUM | 6.2 | — | Aug 11, 2026 | Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by... |
| CVE-2026-17061 | CRITICAL | 10 | — | Aug 11, 2026 | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2... |
| CVE-2026-73210 | MEDIUM | 5.1 | 0.4% | Aug 11, 2026 | A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup o... |
| CVE-2026-51584 | CRITICAL | 9.8 | 0.2% | Aug 11, 2026 | An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S... |
| CVE-2026-51583 | HIGH | 8.5 | 0.2% | Aug 11, 2026 | An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF... |
| CVE-2026-48056 | CRITICAL | 10 | — | Aug 11, 2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro... |
| CVE-2026-48046 | CRITICAL | 9.3 | — | Aug 11, 2026 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai... |
| CVE-2026-46670 | CRITICAL | 9.8 | — | Aug 11, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp... |
| CVE-2026-19539 | HIGH | 8.6 | 0.3% | Aug 11, 2026 | Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5... |
| CVE-2026-19434 | MEDIUM | 5.1 | 0.3% | Aug 11, 2026 | Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute ar... |
| CVE-2026-72785 | CRITICAL | 9.3 | — | Aug 11, 2026 | Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now