2026 CVE Vulnerabilities

57,052 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-51605HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unaut...
CVE-2026-51604HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51603HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51602HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51601HIGH7.5Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to valid...
CVE-2026-51600HIGH7.5Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIB...
CVE-2026-51599CRITICAL9.8An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n al...
CVE-2026-51598MEDIUM6.5An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allo...
CVE-2026-51597CRITICAL9.1MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authenticat...
CVE-2026-15308HIGH7.5The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark...
CVE-2026-15194LOW3.3A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/co...
CVE-2026-15193MEDIUM5.3A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of...
CVE-2026-15192MEDIUM6.5A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/posta...
CVE-2026-15191MEDIUM6.3A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettl...
CVE-2026-15190HIGH7.3A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of...
CVE-2026-13462HIGH7.5PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to ...
CVE-2026-13461CRITICAL9.6When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 ...
CVE-2026-61474MEDIUM5.3An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to a...
CVE-2026-59208MEDIUM6.8n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances confi...
CVE-2026-59207MEDIUM6.5n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce th...
CVE-2026-59206HIGH7.1n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with t...
CVE-2026-58125Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-42486CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23562CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23561CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now