2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18556 | HIGH | 7.4 | 0.3% | Aug 1, 2026 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.... |
| CVE-2026-55735 | HIGH | 7.5 | 0.2% | Aug 1, 2026 | Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi... |
| CVE-2026-55734 | HIGH | 7.5 | 0.1% | Aug 1, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a... |
| CVE-2026-55733 | HIGH | 7.5 | 0.1% | Aug 1, 2026 | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c... |
| CVE-2026-54894 | HIGH | 7.5 | 0.1% | Aug 1, 2026 | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c... |
| CVE-2026-67355 | HIGH | 8.2 | 0.2% | Aug 1, 2026 | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain... |
| CVE-2026-67354 | HIGH | 8.2 | 0.3% | Aug 1, 2026 | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the... |
| CVE-2026-67352 | HIGH | 7.6 | 0.2% | Aug 1, 2026 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows ... |
| CVE-2026-67344 | HIGH | 8.5 | 0.1% | Aug 1, 2026 | ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP... |
| CVE-2026-67343 | HIGH | 8.8 | 0.3% | Aug 1, 2026 | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing a... |
| CVE-2026-67337 | HIGH | 7.1 | 0.3% | Aug 1, 2026 | better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e... |
| CVE-2026-67333 | HIGH | 7.2 | 0.2% | Aug 1, 2026 | better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redi... |
| CVE-2026-67331 | HIGH | 8.7 | 0.2% | Aug 1, 2026 | better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator b... |
| CVE-2026-67329 | HIGH | 7.1 | 0.2% | Aug 1, 2026 | @better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization b... |
| CVE-2026-67328 | HIGH | 8.6 | 0.3% | Aug 1, 2026 | @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling ... |
| CVE-2026-67327 | HIGH | 8.7 | 0.2% | Aug 1, 2026 | better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable... |
| CVE-2026-67326 | HIGH | 7.3 | 0.2% | Aug 1, 2026 | GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attac... |
| CVE-2026-67325 | HIGH | 8.8 | 1.5% | Aug 1, 2026 | GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option p... |
| CVE-2026-67323 | HIGH | 8.6 | 1.0% | Aug 1, 2026 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and g... |
| CVE-2026-67322 | HIGH | 8.7 | 0.3% | Aug 1, 2026 | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied rem... |
| CVE-2026-67320 | HIGH | 8.3 | 0.3% | Aug 1, 2026 | axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hard... |
| CVE-2026-67311 | HIGH | 8.2 | 0.3% | Aug 1, 2026 | Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail... |
| CVE-2026-67309 | HIGH | 7.8 | 0.5% | Aug 1, 2026 | Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider... |
| CVE-2026-67307 | HIGH | 7 | 0.2% | Aug 1, 2026 | Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inven... |
| CVE-2026-67304 | HIGH | 8.7 | 0.4% | Aug 1, 2026 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now