2026 CVE Vulnerabilities

61,340 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29114LOW2.3A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ...
CVE-2026-11815MEDIUM5.3An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote...
CVE-2026-10846HIGH7.5NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks m...
CVE-2026-26241CRITICAL9.1A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu...
CVE-2026-26240CRITICAL9.1A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu...
CVE-2026-11837HIGH7.3A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() ...
CVE-2026-26239HIGH8.1A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t...
CVE-2026-26237HIGH7.5A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul...
CVE-2026-24724HIGH8.1An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a...
CVE-2026-24720MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a r...
CVE-2026-24719HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2026-24717MEDIUM6.5A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ...
CVE-2026-24716HIGH7.2A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote...
CVE-2026-22899MEDIUM6.5A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a...
CVE-2026-22893HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2026-46532MEDIUM4.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0...
CVE-2026-45542HIGH7.1ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-45541HIGH7.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-45329MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu...
CVE-2026-45328HIGH8.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee componen...
CVE-2026-45160MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-46546MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...
CVE-2026-44634HIGH8.7SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are mu...
CVE-2026-53675MEDIUM5.3BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any aut...
CVE-2026-53674HIGH7.1BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when user...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now