2026 CVE Vulnerabilities

61,320 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45416HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-44894HIGH7.5Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke...
CVE-2026-44893HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior t...
CVE-2026-44205MEDIUM6.9Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user prof...
CVE-2026-41581MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Inject...
CVE-2026-10557CRITICAL9.8The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and a...
CVE-2026-28975MEDIUM6.9### Impact When `NIOHTTPRequestDecompressor` is configured with `.ratio(N)`, the decompression limit is enforced using ...
CVE-2026-28980HIGH8.7### Summary The `HTTPDecoder` in `NIOHTTP1` enforces no limit on the total size of an HTTP/1 message's header block or ...
CVE-2026-43671HIGH8.3### Summary A program using swift-nio is vulnerable to a potential out-of-bounds write when attacker-controlled index o...
CVE-2026-28970MEDIUM6.3Programs using swift-nio is vulnerable to HTTP request smuggling and HTTP response splitting attacks, caused by insuffic...
CVE-2026-54102Rejected reason: Reserved but no longer needed.
CVE-2026-54101Rejected reason: Reserved but no longer needed.
CVE-2026-49993MEDIUM5.7Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from vers...
CVE-2026-47200MEDIUM5.3Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 ...
CVE-2026-46342MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 t...
CVE-2026-45670MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions ...
CVE-2026-45669MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to b...
CVE-2026-1836MEDIUM5.3The system stores the username and password from the login form after submitting the request. This could allow an attack...
CVE-2026-12066HIGH7.3A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi...
CVE-2026-12065LOW1.8A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown ...
CVE-2026-11967HIGH8.5MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma...
CVE-2026-11879HIGH8.5MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali...
CVE-2026-49347MEDIUM5.3Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly ...
CVE-2026-48485LOW2.1Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, un...
CVE-2026-47197HIGH7.2Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now