2026 CVE Vulnerabilities

43,494 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-10675MEDIUM6.5In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the ...
CVE-2026-10674MEDIUM5.5The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, cal...
CVE-2026-65058MEDIUM5.9Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155...
CVE-2026-65055MEDIUM6.9Taiga 6.10.1 contains a missing authorization vulnerability that allows unauthenticated attackers to disclose the full m...
CVE-2026-64822MEDIUM6.9djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi...
CVE-2026-64821MEDIUM5.3djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated...
CVE-2026-63140MEDIUM6.5Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A ...
CVE-2026-63139MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-63136MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP...
CVE-2026-63092MEDIUM5.3kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a...
CVE-2026-52475MEDIUM6.1Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the ...
CVE-2026-47714MEDIUM6.1libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code i...
CVE-2026-47689MEDIUM5.2FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1....
CVE-2026-47143MEDIUM5.9Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMR...
CVE-2026-46556MEDIUM6.5FlaskBB is a Forum Software written in Python using the micro framework Flask. Prior to version 2.2.1, a Server-Side Req...
CVE-2026-45383MEDIUM6.9libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow...
CVE-2026-45382MEDIUM6.9libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_sl...
CVE-2026-16318MEDIUM6.9The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store th...
CVE-2026-12139MEDIUM4.4Tanium addressed an information disclosure vulnerability in Connect.
CVE-2026-65069MEDIUM4Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_...
CVE-2026-65065MEDIUM5.5Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without ...
CVE-2026-64613MEDIUM6.2Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOL...
CVE-2026-59143MEDIUM6.3Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offse...
CVE-2026-56146MEDIUM5.4Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configur...
CVE-2026-56145MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now