2026 CVE Vulnerabilities
43,564 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18412 | CRITICAL | 9.1 | 0.2% | Aug 10, 2026 | OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 exten... |
| CVE-2026-72751 | MEDIUM | 5.1 | — | Aug 10, 2026 | CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise... |
| CVE-2026-71959 | MEDIUM | 5.8 | — | Aug 10, 2026 | Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c... |
| CVE-2026-63106 | CRITICAL | 9.8 | — | Aug 10, 2026 | ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the... |
| CVE-2026-63105 | MEDIUM | 5.4 | — | Aug 10, 2026 | ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated custome... |
| CVE-2026-59112 | MEDIUM | 4.4 | — | Aug 10, 2026 | Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability ... |
| CVE-2026-18503 | LOW | 2.4 | 0.1% | Aug 10, 2026 | Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume si... |
| CVE-2026-18478 | MEDIUM | 5.1 | — | Aug 10, 2026 | Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrar... |
| CVE-2026-16742 | MEDIUM | 6.7 | — | Aug 10, 2026 | systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed... |
| CVE-2026-15060 | MEDIUM | 4.7 | — | Aug 10, 2026 | When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o... |
| CVE-2026-15059 | MEDIUM | 5.5 | — | Aug 10, 2026 | Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traver... |
| CVE-2026-72692 | HIGH | 7.5 | — | Aug 10, 2026 | A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote att... |
| CVE-2026-72691 | HIGH | 7.5 | — | Aug 10, 2026 | An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at... |
| CVE-2026-72690 | HIGH | 7.1 | — | Aug 10, 2026 | An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i... |
| CVE-2026-72689 | HIGH | 7.5 | — | Aug 10, 2026 | A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticate... |
| CVE-2026-72688 | HIGH | 7.5 | — | Aug 10, 2026 | A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at... |
| CVE-2026-6374 | HIGH | 7.3 | — | Aug 10, 2026 | Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executab... |
| CVE-2026-6373 | MEDIUM | 6.5 | — | Aug 10, 2026 | Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow... |
| CVE-2026-68428 | — | — | — | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module r... |
| CVE-2026-68427 | — | — | — | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_... |
| CVE-2026-68426 | — | — | — | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals... |
| CVE-2026-68425 | — | — | — | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reasse... |
| CVE-2026-68424 | — | — | — | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: virt_concat: fix use-after-free in mtd_virt_co... |
| CVE-2026-68423 | — | — | — | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: virt_concat: fix use-after-free in mtd_virt_co... |
| CVE-2026-68422 | — | — | — | Aug 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix root leak if its reloc root is unexpecte... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now