2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18651 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr... |
| CVE-2026-18508 | MEDIUM | 4.4 | 0.1% | Aug 3, 2026 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin... |
| CVE-2026-15430 | MEDIUM | 6.2 | — | Aug 3, 2026 | Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, ... |
| CVE-2026-69094 | MEDIUM | 5.3 | — | Aug 3, 2026 | Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_fu... |
| CVE-2026-69092 | MEDIUM | 6.9 | — | Aug 3, 2026 | Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo... |
| CVE-2026-69090 | MEDIUM | 6.9 | — | Aug 3, 2026 | Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm... |
| CVE-2026-68585 | MEDIUM | 6.9 | — | Aug 3, 2026 | SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r... |
| CVE-2026-56609 | MEDIUM | 6.5 | 0.1% | Aug 3, 2026 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using... |
| CVE-2026-56608 | MEDIUM | 5.3 | 0.2% | Aug 3, 2026 | HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce... |
| CVE-2026-68742 | MEDIUM | 5.5 | — | Aug 3, 2026 | A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen ... |
| CVE-2026-69075 | MEDIUM | 6.9 | — | Aug 3, 2026 | FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-c... |
| CVE-2026-63563 | MEDIUM | 6.9 | 0.4% | Aug 3, 2026 | Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication ... |
| CVE-2026-62416 | MEDIUM | 6.9 | 0.4% | Aug 3, 2026 | Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir... |
| CVE-2026-60011 | MEDIUM | 6.9 | 0.2% | Aug 3, 2026 | Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image... |
| CVE-2026-8794 | MEDIUM | 6.9 | 0.7% | Aug 3, 2026 | PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote atta... |
| CVE-2026-8793 | MEDIUM | 6.9 | 0.7% | Aug 3, 2026 | PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticat... |
| CVE-2026-28147 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templa... |
| CVE-2026-18593 | MEDIUM | 5.6 | 0.3% | Aug 3, 2026 | A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/te... |
| CVE-2026-18592 | MEDIUM | 4.7 | 0.2% | Aug 3, 2026 | A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of ... |
| CVE-2026-18590 | MEDIUM | 6.3 | 1.1% | Aug 3, 2026 | A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file ad... |
| CVE-2026-12259 | MEDIUM | 5.3 | 0.1% | Aug 3, 2026 | In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to ... |
| CVE-2026-16565 | MEDIUM | 4.3 | 0.1% | Aug 3, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify produc... |
| CVE-2026-16564 | MEDIUM | 4.3 | 0.1% | Aug 3, 2026 | The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ... |
| CVE-2026-16563 | MEDIUM | 6.5 | 0.1% | Aug 3, 2026 | The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when return... |
| CVE-2026-16297 | MEDIUM | 4.1 | 0.2% | Aug 3, 2026 | The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-impor... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now