2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73431 | HIGH | 8.8 | — | Aug 12, 2026 | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac... |
| CVE-2026-73291 | HIGH | 7.1 | — | Aug 12, 2026 | Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'... |
| CVE-2026-73289 | HIGH | 8.1 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: ... |
| CVE-2026-73286 | HIGH | 8.1 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a... |
| CVE-2026-73285 | HIGH | 7.5 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a... |
| CVE-2026-73284 | HIGH | 8.8 | — | Aug 12, 2026 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi... |
| CVE-2026-73264 | HIGH | 7.6 | — | Aug 12, 2026 | Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce... |
| CVE-2026-68757 | HIGH | 7.5 | — | Aug 12, 2026 | A user with access to a valid SAML response may impersonate another user under specific conditions. |
| CVE-2026-68752 | HIGH | 7.2 | — | Aug 12, 2026 | A Project Resource Manager may gain broader administrative privileges under specific conditions. |
| CVE-2026-66375 | HIGH | 8.1 | — | Aug 12, 2026 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific... |
| CVE-2026-14478 | HIGH | 7.8 | — | Aug 12, 2026 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in... |
| CVE-2026-47231 | HIGH | 8.1 | — | Aug 12, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c... |
| CVE-2026-70468 | HIGH | 8.1 | — | Aug 12, 2026 | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.... |
| CVE-2026-57858 | HIGH | 8.9 | — | Aug 12, 2026 | Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa... |
| CVE-2026-53996 | HIGH | 7 | — | Aug 12, 2026 | NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unpr... |
| CVE-2026-70465 | HIGH | 8.1 | — | Aug 12, 2026 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.... |
| CVE-2026-11325 | HIGH | 8.8 | — | Aug 12, 2026 | Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, ... |
| CVE-2026-19426 | HIGH | 8.8 | — | Aug 12, 2026 | POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directl... |
| CVE-2026-19594 | HIGH | 8.1 | — | Aug 12, 2026 | Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep... |
| CVE-2026-18789 | HIGH | 7.5 | — | Aug 12, 2026 | The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, ... |
| CVE-2026-18474 | HIGH | 8.6 | — | Aug 12, 2026 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta... |
| CVE-2026-64954 | HIGH | 8.2 | — | Aug 12, 2026 | Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th... |
| CVE-2026-12234 | HIGH | 7.8 | — | Aug 12, 2026 | The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn... |
| CVE-2026-18961 | HIGH | 8.1 | — | Aug 12, 2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera... |
| CVE-2026-73122 | HIGH | 7.7 | — | Aug 12, 2026 | A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now