2026 CVE Vulnerabilities
43,380 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72900 | HIGH | 7.1 | — | Aug 10, 2026 | Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. |
| CVE-2026-72899 | CRITICAL | 10 | — | Aug 10, 2026 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes... |
| CVE-2026-72898 | CRITICAL | 10 | 1.1% | Aug 10, 2026 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a... |
| CVE-2026-72862 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, pos... |
| CVE-2026-72740 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git... |
| CVE-2026-72739 | MEDIUM | 6.5 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs... |
| CVE-2026-72738 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoin... |
| CVE-2026-72737 | CRITICAL | 9.6 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and ... |
| CVE-2026-72736 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values d... |
| CVE-2026-72735 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/se... |
| CVE-2026-72734 | HIGH | 8.4 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutatio... |
| CVE-2026-72733 | CRITICAL | 9.9 | — | Aug 10, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s... |
| CVE-2026-72732 | MEDIUM | 4.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp... |
| CVE-2026-70622 | HIGH | 7.1 | — | Aug 10, 2026 | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t... |
| CVE-2026-48159 | CRITICAL | 9.3 | — | Aug 10, 2026 | use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the def... |
| CVE-2026-16626 | CRITICAL | 9.3 | 0.3% | Aug 10, 2026 | Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server... |
| CVE-2026-10754 | HIGH | 8.6 | 0.6% | Aug 10, 2026 | Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may ... |
| CVE-2026-72731 | HIGH | 7.1 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l... |
| CVE-2026-72730 | HIGH | 8.7 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Edit... |
| CVE-2026-72729 | LOW | 2 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca... |
| CVE-2026-72728 | MEDIUM | 6.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed ... |
| CVE-2026-72727 | MEDIUM | 4.8 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged us... |
| CVE-2026-71577 | MEDIUM | 6.3 | — | Aug 10, 2026 | A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed... |
| CVE-2026-71576 | HIGH | 8.5 | 0.1% | Aug 10, 2026 | A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming ... |
| CVE-2026-63623 | MEDIUM | 5.5 | — | Aug 10, 2026 | A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were tempora... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now