2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18719 | MEDIUM | 6.3 | 0.2% | Aug 4, 2026 | A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the compo... |
| CVE-2026-58045 | MEDIUM | 6.2 | — | Aug 4, 2026 | A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:z... |
| CVE-2026-58042 | MEDIUM | 5.9 | — | Aug 4, 2026 | A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Rec... |
| CVE-2026-58041 | MEDIUM | 5.3 | — | Aug 4, 2026 | A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont... |
| CVE-2026-66325 | MEDIUM | 6.1 | 0.4% | Aug 4, 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofin... |
| CVE-2026-66322 | MEDIUM | 5.4 | 0.3% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne... |
| CVE-2026-66317 | MEDIUM | 5.4 | 0.2% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n... |
| CVE-2026-66316 | MEDIUM | 5.4 | 0.2% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne... |
| CVE-2026-66314 | MEDIUM | 5.3 | 0.7% | Aug 4, 2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to ... |
| CVE-2026-66313 | MEDIUM | 6.8 | 0.2% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-66311 | MEDIUM | 6.2 | 0.4% | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |
| CVE-2026-65804 | MEDIUM | 6.1 | 0.4% | Aug 4, 2026 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized atta... |
| CVE-2026-11835 | MEDIUM | 5.6 | 0.1% | Aug 4, 2026 | Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateRese... |
| CVE-2026-67673 | MEDIUM | 4.6 | 0.1% | Aug 3, 2026 | A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is... |
| CVE-2026-69248 | MEDIUM | 6.9 | — | Aug 3, 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0,... |
| CVE-2026-67617 | MEDIUM | 4.8 | 0.2% | Aug 3, 2026 | Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al... |
| CVE-2026-67616 | MEDIUM | 5.3 | 0.3% | Aug 3, 2026 | Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoi... |
| CVE-2026-48115 | MEDIUM | 6.3 | 0.2% | Aug 3, 2026 | Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but... |
| CVE-2026-46714 | MEDIUM | 5.1 | 0.3% | Aug 3, 2026 | Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a... |
| CVE-2026-69245 | MEDIUM | 6.5 | — | Aug 3, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of ... |
| CVE-2026-69243 | MEDIUM | 6.3 | 0.3% | Aug 3, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were v... |
| CVE-2026-52520 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/... |
| CVE-2026-49132 | MEDIUM | 5.4 | 0.1% | Aug 3, 2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec... |
| CVE-2026-49131 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir... |
| CVE-2026-48061 | MEDIUM | 5.9 | — | Aug 3, 2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now