2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71211 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr... |
| CVE-2026-71209 | HIGH | 7.5 | 0.7% | Aug 5, 2026 | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes agai... |
| CVE-2026-71206 | HIGH | 8.3 | 0.2% | Aug 5, 2026 | Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded... |
| CVE-2026-71202 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only cl... |
| CVE-2026-70378 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is posit... |
| CVE-2026-70377 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * rat... |
| CVE-2026-6639 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2026-6627 | HIGH | 8.2 | 0.6% | Aug 5, 2026 | The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a... |
| CVE-2026-6147 | HIGH | 8.8 | 0.7% | Aug 5, 2026 | The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2026-6079 | HIGH | 7.3 | 0.4% | Aug 5, 2026 | The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing... |
| CVE-2026-6020 | HIGH | 7.2 | 0.5% | Aug 5, 2026 | The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action ... |
| CVE-2026-64581 | HIGH | 7.8 | 0.1% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_pol... |
| CVE-2026-64580 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netde... |
| CVE-2026-64578 | HIGH | 8.2 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before readin... |
| CVE-2026-64577 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_ech... |
| CVE-2026-64576 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate... |
| CVE-2026-64575 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc ... |
| CVE-2026-64574 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update e... |
| CVE-2026-64570 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on a... |
| CVE-2026-64568 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double f... |
| CVE-2026-64567 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries th... |
| CVE-2026-61485 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af... |
| CVE-2026-61483 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al... |
| CVE-2026-59675 | HIGH | 7.5 | — | Aug 5, 2026 | When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz... |
| CVE-2026-55997 | HIGH | 8.8 | 0.1% | Aug 5, 2026 | Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now