2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10709 | HIGH | 7.8 | — | Aug 4, 2026 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab... |
| CVE-2026-14838 | HIGH | 7.4 | — | Aug 4, 2026 | Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. ... |
| CVE-2026-67243 | HIGH | 8.6 | — | Aug 4, 2026 | freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the hig... |
| CVE-2026-18759 | HIGH | 8.5 | — | Aug 4, 2026 | The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication... |
| CVE-2026-18755 | HIGH | 7.3 | — | Aug 4, 2026 | A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di... |
| CVE-2026-64563 | HIGH | 7.8 | 0.1% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart r... |
| CVE-2026-64562 | HIGH | 8.8 | 0.2% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR fr... |
| CVE-2026-64561 | HIGH | 8.8 | 0.2% | Aug 4, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* m... |
| CVE-2026-16623 | HIGH | 8 | 0.2% | Aug 4, 2026 | The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a g... |
| CVE-2026-16881 | HIGH | 8.7 | 0.3% | Aug 4, 2026 | A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component... |
| CVE-2026-42169 | HIGH | 7.3 | 0.1% | Aug 4, 2026 | A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `f... |
| CVE-2026-14818 | HIGH | 7.2 | 0.4% | Aug 4, 2026 | A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versi... |
| CVE-2026-6837 | HIGH | 7.2 | 0.9% | Aug 4, 2026 | A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions... |
| CVE-2026-56846 | HIGH | 7.5 | — | Aug 4, 2026 | A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memor... |
| CVE-2026-56845 | HIGH | 7.5 | — | Aug 4, 2026 | An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configur... |
| CVE-2026-66326 | HIGH | 8.8 | 0.7% | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66318 | HIGH | 8.1 | 0.4% | Aug 4, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ... |
| CVE-2026-66315 | HIGH | 7.5 | 0.6% | Aug 4, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. |
| CVE-2026-66312 | HIGH | 8.8 | 1.0% | Aug 4, 2026 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |
| CVE-2026-66310 | HIGH | 7.1 | 0.4% | Aug 4, 2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat... |
| CVE-2026-65802 | HIGH | 7.4 | 0.9% | Aug 4, 2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose informat... |
| CVE-2026-62870 | HIGH | 8.8 | 0.8% | Aug 4, 2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. |
| CVE-2026-67978 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmittin... |
| CVE-2026-48399 | HIGH | 7.5 | 0.5% | Aug 3, 2026 | Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a... |
| CVE-2026-69249 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now