2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47613 | HIGH | 7.5 | 0.3% | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a rest... |
| CVE-2026-47612 | HIGH | 7.5 | 0.5% | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper lim... |
| CVE-2026-24255 | HIGH | 7.5 | 0.3% | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash... |
| CVE-2026-24253 | HIGH | 8.2 | 0.3% | Aug 4, 2026 | NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful expl... |
| CVE-2026-18830 | HIGH | 8.6 | 0.3% | Aug 4, 2026 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute co... |
| CVE-2026-18788 | HIGH | 7.3 | 0.4% | Aug 4, 2026 | A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown fun... |
| CVE-2026-69263 | HIGH | 8.7 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation ... |
| CVE-2026-69262 | HIGH | 7.1 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1... |
| CVE-2026-69258 | HIGH | 8.8 | 0.4% | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthentic... |
| CVE-2026-69257 | HIGH | 7.6 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP ... |
| CVE-2026-64634 | HIGH | 8.4 | — | Aug 4, 2026 | A vulnerability allowing local privilege escalation to the Reporter service context. |
| CVE-2026-64631 | HIGH | 8.5 | — | Aug 4, 2026 | A vulnerability allowing a low-privileged user to inject SQL and extract database contents. |
| CVE-2026-58075 | HIGH | 8.7 | — | Aug 4, 2026 | A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leverag... |
| CVE-2026-58074 | HIGH | 8.6 | — | Aug 4, 2026 | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. |
| CVE-2026-58071 | HIGH | 8.2 | — | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A... |
| CVE-2026-58067 | HIGH | 8.7 | — | Aug 4, 2026 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause ... |
| CVE-2026-56848 | HIGH | 7.5 | — | Aug 4, 2026 | A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m... |
| CVE-2026-18787 | HIGH | 8.8 | 1.7% | Aug 4, 2026 | A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fi... |
| CVE-2026-15314 | HIGH | 7.5 | 0.2% | Aug 4, 2026 | Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT... |
| CVE-2026-15307 | HIGH | 8.8 | 0.5% | Aug 4, 2026 | An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse... |
| CVE-2026-69252 | HIGH | 7.2 | — | Aug 4, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/fil... |
| CVE-2026-69100 | HIGH | 8.8 | — | Aug 4, 2026 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i... |
| CVE-2026-25292 | HIGH | 7.6 | 0.2% | Aug 4, 2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration... |
| CVE-2026-25288 | HIGH | 7.4 | 0.2% | Aug 4, 2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. |
| CVE-2026-24084 | HIGH | 7.5 | 0.2% | Aug 4, 2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed cap... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now