2026 CVE Vulnerabilities

57,114 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58460HIGH7.7react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious applicat...
CVE-2026-52830CRITICAL9.4fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining t...
CVE-2026-52192HIGH7.5An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead...
CVE-2026-52191HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52189HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-52188MEDIUM6.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-38972HIGH7.8Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Not...
CVE-2026-38971CRITICAL9.1ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_contr...
CVE-2026-38970HIGH7.5pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The pars...
CVE-2026-38969Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-38968CRITICAL9.8ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session ide...
CVE-2026-59102MEDIUM5.4Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execut...
CVE-2026-59101MEDIUM6.9AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote ...
CVE-2026-59100MEDIUM5LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to...
CVE-2026-59099CRITICAL9.3Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to...
CVE-2026-59098HIGH7.1LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic sea...
CVE-2026-59097MEDIUM6.9Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to creat...
CVE-2026-59096HIGH8.2Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document ...
CVE-2026-59095HIGH8.3LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attacker...
CVE-2026-59094HIGH8.7Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed docume...
CVE-2026-59093HIGH8.8Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted...
CVE-2026-59092CRITICAL9.8JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthentica...
CVE-2026-58580MEDIUM6LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. ...
CVE-2026-58579MEDIUM5.4RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalize...
CVE-2026-58578HIGH7.1LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now