2026 CVE Vulnerabilities
43,380 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72724 | MEDIUM | 4.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, plugins/chat/lib/c... |
| CVE-2026-72723 | MEDIUM | 5.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano... |
| CVE-2026-72722 | MEDIUM | 4.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, TopicLink.extract_... |
| CVE-2026-72721 | MEDIUM | 5.3 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec... |
| CVE-2026-72720 | MEDIUM | 6.4 | — | Aug 10, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse... |
| CVE-2026-72719 | MEDIUM | 6.7 | — | Aug 10, 2026 | Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transf... |
| CVE-2026-72718 | HIGH | 7 | — | Aug 10, 2026 | goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system... |
| CVE-2026-66738 | HIGH | 8.8 | — | Aug 10, 2026 | SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint ... |
| CVE-2026-56620 | MEDIUM | 4.3 | — | Aug 10, 2026 | HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error repor... |
| CVE-2026-48158 | CRITICAL | 9.3 | — | Aug 10, 2026 | use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34,... |
| CVE-2026-48048 | HIGH | 7.5 | — | Aug 10, 2026 | XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Sta... |
| CVE-2026-47754 | CRITICAL | 9.3 | — | Aug 10, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19... |
| CVE-2026-72761 | MEDIUM | 6.9 | — | Aug 10, 2026 | The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses afte... |
| CVE-2026-72760 | MEDIUM | 5.3 | — | Aug 10, 2026 | Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. Whe... |
| CVE-2026-72759 | MEDIUM | 6.9 | — | Aug 10, 2026 | In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization... |
| CVE-2026-19433 | HIGH | 8.6 | — | Aug 10, 2026 | Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before ... |
| CVE-2026-18412 | CRITICAL | 9.1 | 0.2% | Aug 10, 2026 | OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 exten... |
| CVE-2026-72751 | MEDIUM | 5.1 | — | Aug 10, 2026 | CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise... |
| CVE-2026-71959 | MEDIUM | 5.8 | — | Aug 10, 2026 | Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c... |
| CVE-2026-63106 | CRITICAL | 9.8 | — | Aug 10, 2026 | ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the... |
| CVE-2026-63105 | MEDIUM | 5.4 | — | Aug 10, 2026 | ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome... |
| CVE-2026-59112 | MEDIUM | 4.4 | — | Aug 10, 2026 | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability ... |
| CVE-2026-18503 | LOW | 2.4 | 0.1% | Aug 10, 2026 | Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume si... |
| CVE-2026-18478 | MEDIUM | 5.1 | — | Aug 10, 2026 | Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrar... |
| CVE-2026-16742 | MEDIUM | 6.7 | — | Aug 10, 2026 | systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now