2026 CVE Vulnerabilities

59,953 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13495MEDIUM4.7A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the fi...
CVE-2026-13493LOW3.1A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file ba...
CVE-2026-13491LOW3.7A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetIn...
CVE-2026-13490MEDIUM6.3A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document...
CVE-2026-13489LOW3.1A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of t...
CVE-2026-13488HIGH7.3A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vuln...
CVE-2026-13487HIGH7.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function ...
CVE-2026-13486HIGH7.3A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown fu...
CVE-2026-13485HIGH7.3A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of t...
CVE-2026-13484HIGH8.8A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unkn...
CVE-2026-13483LOW3.1A flaw has been found in arc53 DocsGPT up to 0.18.0. The affected element is the function encrypt_credentials of the fil...
CVE-2026-13482LOW3.7A vulnerability was detected in skypilot-org skypilot up to 0.12.0. Impacted is the function username.encode of the file...
CVE-2026-10646HIGH7.4Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-all...
CVE-2026-10644LOW3.1The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains ...
CVE-2026-10593MEDIUM6.5The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications....
CVE-2026-58058MEDIUM6.9Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (li...
CVE-2026-58057MEDIUM5Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparis...
CVE-2026-58056HIGH7.6RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type...
CVE-2026-58055MEDIUM6.3nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header an...
CVE-2026-58054Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE was assigned on the...
CVE-2026-58053CRITICAL9.9Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke...
CVE-2026-58052MEDIUM4.87-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because it...
CVE-2026-58051HIGH8.3libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsin...
CVE-2026-58050HIGH7.5libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses ...
CVE-2026-58049HIGH8.6FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now