2026 CVE Vulnerabilities

61,320 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50084MEDIUM6.5The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to...
CVE-2026-50083CRITICAL9.8The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-...
CVE-2026-50082MEDIUM5.3The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att...
CVE-2026-50026MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in...
CVE-2026-50020MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50011HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50010HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50009MEDIUM4.8Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,...
CVE-2026-48748HIGH7.5Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Fina...
CVE-2026-48059HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-48043HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to ...
CVE-2026-48006HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-47691CRITICAL10Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-47190MEDIUM4.4IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM c...
CVE-2026-47182MEDIUM5.3Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private fi...
CVE-2026-46690MEDIUM5.8unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v...
CVE-2026-45833HIGH8.8A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke...
CVE-2026-45832HIGH8.8All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorizatio...
CVE-2026-45831HIGH8.8The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project eva...
CVE-2026-45830HIGH8.8A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us...
CVE-2026-44976MEDIUM5.3Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard...
CVE-2026-44975MEDIUM5.3Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res...
CVE-2026-44967MEDIUM5.3OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/m...
CVE-2026-44208MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su...
CVE-2026-44207MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now