2026 CVE Vulnerabilities

61,320 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7387HIGH8.8Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to req...
CVE-2026-7184MEDIUM6.5Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API resp...
CVE-2026-6961HIGH7.6Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to san...
CVE-2026-6739HIGH7.2Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-...
CVE-2026-6689MEDIUM4.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce Permiss...
CVE-2026-6046MEDIUM5.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a...
CVE-2026-53982HIGH7.1Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker...
CVE-2026-53981HIGH7.6Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacke...
CVE-2026-47224MEDIUM4.3NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6....
CVE-2026-47222MEDIUM5.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6....
CVE-2026-3840HIGH7.1A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version strin...
CVE-2026-3433MEDIUM4.3Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_u...
CVE-2026-9641MEDIUM5.3Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default alg...
CVE-2026-9638HIGH7.5Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built...
CVE-2026-8828HIGH8.8A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users...
CVE-2026-5792MEDIUM6.5Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Market...
CVE-2026-53568MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerab...
CVE-2026-50560MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50091HIGH7.4Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h...
CVE-2026-50090MEDIUM6.1The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due ...
CVE-2026-50089MEDIUM6.1The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire...
CVE-2026-50088MEDIUM4.7The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara...
CVE-2026-50087MEDIUM6.1The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an inst...
CVE-2026-50086CRITICAL9.8The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke...
CVE-2026-50085CRITICAL9.8The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now