2026 CVE Vulnerabilities
43,347 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72919 | MEDIUM | 4.3 | 0.2% | Aug 10, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7... |
| CVE-2026-72918 | MEDIUM | 5.4 | 0.2% | Aug 10, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7... |
| CVE-2026-72917 | MEDIUM | 5.9 | 0.3% | Aug 10, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-72916 | MEDIUM | 6.3 | — | Aug 10, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be... |
| CVE-2026-72915 | HIGH | 7.5 | 0.3% | Aug 10, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta... |
| CVE-2026-72914 | HIGH | 7.5 | 0.5% | Aug 10, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.21, 4.5.14, 4.6.4, and 4.7.0-be... |
| CVE-2026-6426 | MEDIUM | 4.4 | 0.2% | Aug 10, 2026 | A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size... |
| CVE-2026-73035 | MEDIUM | 5.3 | 0.2% | Aug 10, 2026 | npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t... |
| CVE-2026-73033 | HIGH | 7 | 0.6% | Aug 10, 2026 | Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi... |
| CVE-2026-73030 | HIGH | 8.1 | 0.4% | Aug 10, 2026 | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory func... |
| CVE-2026-72913 | HIGH | 7.3 | 0.1% | Aug 10, 2026 | Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/wind... |
| CVE-2026-72912 | MEDIUM | 4.3 | 0.2% | Aug 10, 2026 | CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec... |
| CVE-2026-72911 | CRITICAL | 9.9 | — | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_templat... |
| CVE-2026-72910 | HIGH | 7.1 | 0.3% | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p... |
| CVE-2026-72909 | HIGH | 7.1 | 0.3% | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayabl... |
| CVE-2026-72908 | MEDIUM | 6.5 | 0.3% | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template... |
| CVE-2026-72907 | MEDIUM | 6.5 | — | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function ... |
| CVE-2026-72906 | MEDIUM | 4.3 | 0.2% | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ... |
| CVE-2026-72905 | — | — | — | Aug 10, 2026 | Rejected reason: Further research determined the issue is not a vulnerability. |
| CVE-2026-72904 | CRITICAL | 9.3 | 0.3% | Aug 10, 2026 | Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file ... |
| CVE-2026-72903 | HIGH | 8.1 | 0.3% | Aug 10, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu... |
| CVE-2026-72743 | MEDIUM | 5.4 | — | Aug 10, 2026 | SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb... |
| CVE-2026-63622 | HIGH | 7.8 | 0.1% | Aug 10, 2026 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploi... |
| CVE-2026-48160 | CRITICAL | 9.3 | 0.4% | Aug 10, 2026 | react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau... |
| CVE-2026-19411 | LOW | 3.9 | 0.1% | Aug 10, 2026 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now