2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7532 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced ... |
| CVE-2026-7511 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bo... |
| CVE-2026-6331 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC ve... |
| CVE-2026-6330 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's i... |
| CVE-2026-6329 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and all... |
| CVE-2026-6325 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write pas... |
| CVE-2026-6092 | MEDIUM | 5.3 | 0.1% | Jun 25, 2026 | When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing E... |
| CVE-2026-55962 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl... |
| CVE-2026-54479 | HIGH | 7.3 | 0.2% | Jun 25, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-50176 | HIGH | 8.7 | 0.4% | Jun 25, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-44622 | MEDIUM | 6.9 | 0.2% | Jun 25, 2026 | Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |
| CVE-2026-40702 | CRITICAL | 9.4 | 0.4% | Jun 25, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res... |
| CVE-2026-22879 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability |
| CVE-2026-13283 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a... |
| CVE-2026-13282 | MEDIUM | 6.8 | 0.1% | Jun 25, 2026 | Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e... |
| CVE-2026-13281 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the rend... |
| CVE-2026-12992 | HIGH | 7.4 | 0.3% | Jun 25, 2026 | A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.ws... |
| CVE-2026-12975 | HIGH | 8.5 | 0.4% | Jun 25, 2026 | A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without ena... |
| CVE-2026-11800 | HIGH | 8.1 | 0.2% | Jun 25, 2026 | A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an a... |
| CVE-2026-11703 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for t... |
| CVE-2026-10098 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose se... |
| CVE-2026-6731 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN... |
| CVE-2026-6681 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written... |
| CVE-2026-6679 | HIGH | 7.5 | 0.4% | Jun 25, 2026 | A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. T... |
| CVE-2026-6678 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now