2026 CVE Vulnerabilities
43,380 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72906 | MEDIUM | 4.3 | 0.2% | Aug 10, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ... |
| CVE-2026-72905 | — | — | — | Aug 10, 2026 | Rejected reason: Further research determined the issue is not a vulnerability. |
| CVE-2026-72904 | CRITICAL | 9.3 | 0.3% | Aug 10, 2026 | Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file ... |
| CVE-2026-72903 | HIGH | 8.1 | 0.3% | Aug 10, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu... |
| CVE-2026-72743 | MEDIUM | 5.4 | — | Aug 10, 2026 | SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb... |
| CVE-2026-63622 | HIGH | 7.8 | 0.1% | Aug 10, 2026 | A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploi... |
| CVE-2026-48160 | CRITICAL | 9.3 | 0.4% | Aug 10, 2026 | react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau... |
| CVE-2026-19411 | LOW | 3.9 | 0.1% | Aug 10, 2026 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al... |
| CVE-2026-18982 | HIGH | 8.8 | 0.5% | Aug 10, 2026 | A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a... |
| CVE-2026-18951 | HIGH | 8.8 | 0.7% | Aug 10, 2026 | A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly ag... |
| CVE-2026-18950 | HIGH | 8.8 | 0.4% | Aug 10, 2026 | A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol... |
| CVE-2026-18949 | HIGH | 8.8 | 0.4% | Aug 10, 2026 | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac... |
| CVE-2026-18948 | CRITICAL | 9.9 | 0.7% | Aug 10, 2026 | A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic... |
| CVE-2026-18947 | HIGH | 8.5 | 0.5% | Aug 10, 2026 | A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental... |
| CVE-2026-18942 | MEDIUM | 5.5 | 0.3% | Aug 10, 2026 | A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th... |
| CVE-2026-18941 | HIGH | 7.7 | 0.6% | Aug 10, 2026 | A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is... |
| CVE-2026-18621 | HIGH | 7.6 | 0.3% | Aug 10, 2026 | A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde... |
| CVE-2026-18620 | HIGH | 7.1 | 0.3% | Aug 10, 2026 | A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab... |
| CVE-2026-18618 | HIGH | 7.5 | 0.5% | Aug 10, 2026 | A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn... |
| CVE-2026-18617 | HIGH | 8.8 | 0.4% | Aug 10, 2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the sp... |
| CVE-2026-18611 | HIGH | 7.5 | 0.4% | Aug 10, 2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive... |
| CVE-2026-18608 | HIGH | 8.7 | 0.4% | Aug 10, 2026 | A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permission... |
| CVE-2026-16456 | MEDIUM | 6.5 | 0.3% | Aug 10, 2026 | A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex... |
| CVE-2026-15581 | HIGH | 8 | 0.2% | Aug 10, 2026 | A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b... |
| CVE-2026-15467 | HIGH | 8.1 | 0.4% | Aug 10, 2026 | A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now