2026 CVE Vulnerabilities
43,031 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73214 | HIGH | 8.2 | — | Aug 11, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and cr... |
| CVE-2026-72713 | HIGH | 8.7 | — | Aug 11, 2026 | XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-cre... |
| CVE-2026-48771 | HIGH | 8.2 | — | Aug 11, 2026 | ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed du... |
| CVE-2026-48767 | HIGH | 7.6 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain ... |
| CVE-2026-48494 | HIGH | 7.1 | — | Aug 11, 2026 | TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resum... |
| CVE-2026-48447 | HIGH | 7.7 | — | Aug 11, 2026 | Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution ... |
| CVE-2026-48441 | HIGH | 8.6 | — | Aug 11, 2026 | Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne... |
| CVE-2026-48416 | HIGH | 7.5 | — | Aug 11, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-48415 | HIGH | 7.6 | — | Aug 11, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A... |
| CVE-2026-48414 | HIGH | 7.7 | — | Aug 11, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged... |
| CVE-2026-48413 | HIGH | 8.7 | — | Aug 11, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged... |
| CVE-2026-48410 | HIGH | 7.8 | — | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48409 | HIGH | 7.8 | — | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48408 | HIGH | 7.8 | — | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48407 | HIGH | 7.8 | — | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48406 | HIGH | 7.8 | — | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48405 | HIGH | 7.8 | — | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48404 | HIGH | 7.8 | — | Aug 11, 2026 | Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in t... |
| CVE-2026-48397 | HIGH | 8.6 | — | Aug 11, 2026 | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code e... |
| CVE-2026-47940 | HIGH | 7.8 | — | Aug 11, 2026 | Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code exe... |
| CVE-2026-73089 | HIGH | 7.5 | — | Aug 11, 2026 | Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to ... |
| CVE-2026-73088 | HIGH | 7.5 | — | Aug 11, 2026 | Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to ... |
| CVE-2026-73086 | HIGH | 7.4 | 0.3% | Aug 11, 2026 | nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the na... |
| CVE-2026-73083 | HIGH | 7.6 | — | Aug 11, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine l... |
| CVE-2026-73081 | HIGH | 8.7 | 0.3% | Aug 11, 2026 | Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now