2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77148 | CRITICAL | 9.9 | 0.5% | Aug 20, 2026 | A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-con... |
| CVE-2026-19586 | CRITICAL | 9.8 | 5.1% | Aug 20, 2026 | A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as a... |
| CVE-2026-73257 | CRITICAL | 9.1 | 0.4% | Aug 20, 2026 | Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can sen... |
| CVE-2026-73256 | CRITICAL | 9.1 | 0.4% | Aug 20, 2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an ... |
| CVE-2026-73253 | CRITICAL | 9.1 | 0.2% | Aug 20, 2026 | Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildca... |
| CVE-2026-73251 | CRITICAL | 9.3 | 0.2% | Aug 20, 2026 | Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server t... |
| CVE-2026-63385 | CRITICAL | 9.2 | 0.4% | Aug 20, 2026 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in ... |
| CVE-2026-63382 | CRITICAL | 9.2 | 0.6% | Aug 20, 2026 | Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsi... |
| CVE-2026-53424 | CRITICAL | 9.1 | 0.3% | Aug 20, 2026 | Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject... |
| CVE-2026-2334 | CRITICAL | 9.4 | 0.5% | Aug 20, 2026 | An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-s... |
| CVE-2026-77022 | CRITICAL | 9.9 | 0.5% | Aug 20, 2026 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the... |
| CVE-2026-71428 | CRITICAL | 9.3 | 0.3% | Aug 20, 2026 | The unstructured library provides open-source components for ingesting and pre-processing images and text documents, suc... |
| CVE-2026-55642 | CRITICAL | 9.8 | 0.4% | Aug 20, 2026 | dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/au... |
| CVE-2026-18265 | CRITICAL | 9.8 | 0.7% | Aug 20, 2026 | OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attacker... |
| CVE-2026-63039 | CRITICAL | 9.8 | 0.4% | Aug 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi... |
| CVE-2026-63038 | CRITICAL | 9.8 | 0.4% | Aug 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi... |
| CVE-2026-63037 | CRITICAL | 9.8 | 0.4% | Aug 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi... |
| CVE-2026-16926 | CRITICAL | 9.1 | 0.3% | Aug 20, 2026 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper... |
| CVE-2026-15706 | CRITICAL | 9.8 | 0.4% | Aug 20, 2026 | Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Bayla... |
| CVE-2026-28164 | CRITICAL | 9.6 | 0.1% | Aug 20, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. ... |
| CVE-2026-18482 | CRITICAL | 9.8 | 1.7% | Aug 20, 2026 | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-... |
| CVE-2026-77071 | CRITICAL | 9.8 | 0.3% | Aug 20, 2026 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row G... |
| CVE-2026-77070 | CRITICAL | 9.8 | 0.2% | Aug 20, 2026 | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and... |
| CVE-2026-74018 | CRITICAL | 9.9 | — | Aug 20, 2026 | Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. |
| CVE-2026-74016 | CRITICAL | 9.9 | — | Aug 20, 2026 | Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now