2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-102281HIGH7.5Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message...
CVE-2026-101205MEDIUM6.3A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PC...
CVE-2026-101204MEDIUM6.3A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe...
CVE-2026-101203MEDIUM6.3A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the c...
CVE-2026-101202MEDIUM6.3A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component ...
CVE-2026-101188HIGH8.3A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd...
CVE-2026-101093MEDIUM5.4Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to de...
CVE-2026-101092MEDIUM5.3SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish r...
CVE-2026-101091HIGH7.1SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyu...
CVE-2026-97027LOW3.6Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.deskto...
CVE-2026-97026LOW3.9Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On m...
CVE-2026-97025LOW3.2Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cac...
CVE-2026-91096——In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destr...
CVE-2026-91095——In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::...
CVE-2026-84895——In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calli...
CVE-2026-18416LOW3.7The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource pa...
CVE-2026-18415MEDIUM6.3ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte trans...
CVE-2026-18414HIGH7.8The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size fi...
CVE-2026-18413HIGH7.8The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size fi...
CVE-2026-16513HIGH7.8The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c...
CVE-2026-102279LOW3.1Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true ...
CVE-2026-102278HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3...
CVE-2026-102277MEDIUM5.3The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3...
CVE-2026-102276HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3...
CVE-2026-102275MEDIUM6.5PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in j...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now