2026 CVE Vulnerabilities
43,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-69247 | HIGH | 8.2 | 0.2% | Aug 3, 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 unti... |
| CVE-2026-67977 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause... |
| CVE-2026-67975 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new s... |
| CVE-2026-67974 | HIGH | 7.5 | 0.2% | Aug 3, 2026 | A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7... |
| CVE-2026-67973 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying f... |
| CVE-2026-67970 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive co... |
| CVE-2026-67969 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset v... |
| CVE-2026-47746 | HIGH | 8.9 | 0.2% | Aug 3, 2026 | Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulne... |
| CVE-2026-10849 | HIGH | 7.5 | 0.3% | Aug 3, 2026 | The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser... |
| CVE-2026-69246 | HIGH | 7.2 | 0.2% | Aug 3, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and... |
| CVE-2026-69244 | HIGH | 7.1 | 0.3% | Aug 3, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap r... |
| CVE-2026-67976 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allo... |
| CVE-2026-67972 | HIGH | 7.5 | 0.1% | Aug 3, 2026 | An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data... |
| CVE-2026-66065 | HIGH | 8.4 | 0.3% | Aug 3, 2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ... |
| CVE-2026-52521 | HIGH | 8.1 | 0.1% | Aug 3, 2026 | A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th... |
| CVE-2026-48113 | HIGH | 8.5 | 0.2% | Aug 3, 2026 | Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client... |
| CVE-2026-41447 | HIGH | 8.5 | 0.1% | Aug 3, 2026 | FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit... |
| CVE-2026-18737 | HIGH | 7.1 | 0.2% | Aug 3, 2026 | Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL... |
| CVE-2026-18733 | HIGH | 8.8 | 0.3% | Aug 3, 2026 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors... |
| CVE-2026-18647 | HIGH | 7.3 | 0.4% | Aug 3, 2026 | A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue ... |
| CVE-2026-69192 | HIGH | 7.7 | 0.3% | Aug 3, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 ac... |
| CVE-2026-69185 | HIGH | 7.5 | — | Aug 3, 2026 | Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp... |
| CVE-2026-68981 | HIGH | 7.5 | 0.3% | Aug 3, 2026 | Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding... |
| CVE-2026-67599 | HIGH | 8.6 | 1.9% | Aug 3, 2026 | ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke... |
| CVE-2026-47211 | HIGH | 8.4 | — | Aug 3, 2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now