2026 CVE Vulnerabilities

61,122 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9697HIGH7.4Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or s...
CVE-2026-9679MEDIUM5.9Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences...
CVE-2026-9678MEDIUM5.9Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control he...
CVE-2026-7300MEDIUM6.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web In...
CVE-2026-6734HIGH8.8Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying t...
CVE-2026-6733LOW3.7Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-con...
CVE-2026-53805CRITICAL9.8NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inf...
CVE-2026-48591MEDIUM4.8Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site...
CVE-2026-47774HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7...
CVE-2026-3894CRITICAL9.1Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects...
CVE-2026-39199LOW2.9snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
CVE-2026-30803CRITICAL9.1Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This ...
CVE-2026-30802HIGH8.2Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connex...
CVE-2026-30799HIGH8.1Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identit...
CVE-2026-2675MEDIUM6.5Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake th...
CVE-2026-2674HIGH8.1Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Servic...
CVE-2026-2467HIGH8.1Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags...
CVE-2026-20266CRITICAL9.1In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands ...
CVE-2026-20265MEDIUM4.3In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles ...
CVE-2026-20178MEDIUM4.3A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker t...
CVE-2026-11525LOW3.7Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or No...
CVE-2026-9675HIGH7.5Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragme...
CVE-2026-53875HIGH7.1picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to e...
CVE-2026-53874CRITICAL9.8picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbit...
CVE-2026-53873CRITICAL9.8picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level pro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now