2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18738 | MEDIUM | 4.7 | — | Aug 3, 2026 | Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att... |
| CVE-2026-18736 | MEDIUM | 5.3 | — | Aug 3, 2026 | Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serve... |
| CVE-2026-18648 | MEDIUM | 5.3 | 0.2% | Aug 3, 2026 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat... |
| CVE-2026-18646 | MEDIUM | 5.5 | 0.5% | Aug 3, 2026 | A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system... |
| CVE-2026-18645 | MEDIUM | 5.4 | 0.4% | Aug 3, 2026 | A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys... |
| CVE-2026-69198 | MEDIUM | 6.9 | 0.3% | Aug 3, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev... |
| CVE-2026-66296 | MEDIUM | 5.1 | 0.3% | Aug 3, 2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sit... |
| CVE-2026-62354 | MEDIUM | 4.3 | 0.3% | Aug 3, 2026 | Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit... |
| CVE-2026-58139 | MEDIUM | 6.5 | — | Aug 3, 2026 | The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S... |
| CVE-2026-18654 | MEDIUM | 6.9 | 0.3% | Aug 3, 2026 | Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v... |
| CVE-2026-18644 | MEDIUM | 5.4 | 0.4% | Aug 3, 2026 | A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /... |
| CVE-2026-18632 | MEDIUM | 6.3 | 0.4% | Aug 3, 2026 | A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of ... |
| CVE-2026-18631 | MEDIUM | 6.3 | 0.4% | Aug 3, 2026 | A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig ... |
| CVE-2026-38446 | MEDIUM | 6.1 | — | Aug 3, 2026 | A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread e... |
| CVE-2026-38444 | MEDIUM | 6.1 | — | Aug 3, 2026 | osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is... |
| CVE-2026-69153 | MEDIUM | 5.3 | 0.4% | Aug 3, 2026 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ... |
| CVE-2026-69151 | MEDIUM | 6.1 | 0.3% | Aug 3, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-69149 | MEDIUM | 6.1 | 0.3% | Aug 3, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-68945 | MEDIUM | 6.1 | 0.2% | Aug 3, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-68930 | MEDIUM | 6.5 | — | Aug 3, 2026 | Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci... |
| CVE-2026-67612 | MEDIUM | 4.8 | — | Aug 3, 2026 | OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al... |
| CVE-2026-18610 | MEDIUM | 5.5 | 0.4% | Aug 3, 2026 | A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp... |
| CVE-2026-18604 | MEDIUM | 5.3 | 0.1% | Aug 3, 2026 | A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function D... |
| CVE-2026-18477 | MEDIUM | 4.4 | 0.1% | Aug 3, 2026 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a... |
| CVE-2026-18243 | MEDIUM | 6.9 | — | Aug 3, 2026 | Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now