2026 CVE Vulnerabilities
42,999 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49262 | LOW | 3 | — | Aug 12, 2026 | In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is ... |
| CVE-2026-70467 | LOW | 3.8 | — | Aug 12, 2026 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM... |
| CVE-2026-18044 | LOW | 3.7 | — | Aug 12, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use... |
| CVE-2026-64951 | LOW | 3.5 | — | Aug 12, 2026 | A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic... |
| CVE-2026-73283 | LOW | 2.5 | — | Aug 11, 2026 | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwar... |
| CVE-2026-73281 | LOW | 3.5 | — | Aug 11, 2026 | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, includi... |
| CVE-2026-65655 | LOW | 2.3 | — | Aug 11, 2026 | When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to ... |
| CVE-2026-48412 | LOW | 2.7 | — | Aug 11, 2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An att... |
| CVE-2026-73087 | LOW | 2.3 | — | Aug 11, 2026 | Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal... |
| CVE-2026-28729 | LOW | 2.4 | — | Aug 11, 2026 | Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System softw... |
| CVE-2026-25194 | LOW | 1.8 | — | Aug 11, 2026 | Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adve... |
| CVE-2026-73071 | LOW | 3.3 | — | Aug 11, 2026 | Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can reta... |
| CVE-2026-11736 | LOW | 1.9 | — | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make ... |
| CVE-2026-11735 | LOW | 1.9 | — | Aug 11, 2026 | A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to ma... |
| CVE-2026-11734 | LOW | 1.1 | — | Aug 11, 2026 | A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected de... |
| CVE-2026-11733 | LOW | 1.1 | — | Aug 11, 2026 | A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the ... |
| CVE-2026-73157 | LOW | 2.3 | 0.3% | Aug 11, 2026 | Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface usi... |
| CVE-2026-11985 | LOW | 3.6 | 0.1% | Aug 11, 2026 | On the Zephyr ARM port, enabling the hardware FPU (CONFIG_FPU) forces the "Floating point ABI" choice, which defaults to... |
| CVE-2026-66774 | LOW | 3.7 | 0.2% | Aug 11, 2026 | SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this ... |
| CVE-2026-58245 | LOW | 3.8 | 0.2% | Aug 11, 2026 | SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of th... |
| CVE-2026-58239 | LOW | 3.7 | 0.2% | Aug 11, 2026 | SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send ... |
| CVE-2026-44762 | LOW | 3.7 | 0.1% | Aug 11, 2026 | SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c... |
| CVE-2026-11812 | LOW | 2.5 | — | Aug 10, 2026 | The UpdateHub management subsystem (subsys/mgmt/updatehub/updatehub.c) drives every update operation through a single fi... |
| CVE-2026-11811 | LOW | 3.7 | — | Aug 10, 2026 | The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS ... |
| CVE-2026-19411 | LOW | 3.9 | 0.1% | Aug 10, 2026 | A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now