2026 CVE Vulnerabilities

61,770 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45287MEDIUM5.5OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1...
CVE-2026-44393HIGH7.4An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe...
CVE-2026-43986CRITICAL9.9Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public ...
CVE-2026-43985HIGH8.8Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUp...
CVE-2026-43984HIGH8.9Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_e...
CVE-2026-41178MEDIUM5.3OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and ...
CVE-2026-40930MEDIUM5.4LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. I...
CVE-2026-38570HIGH7.5bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial o...
CVE-2026-36182CRITICAL9.8GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing atta...
CVE-2026-10868CRITICAL9A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplie...
CVE-2026-10815MEDIUM6.3A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. Thi...
CVE-2026-10814HIGH7A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file int...
CVE-2026-10813LOW3.6A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integratio...
CVE-2026-47707MEDIUM5.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter ext...
CVE-2026-47706MEDIUM5.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter ext...
CVE-2026-45739MEDIUM4.3Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled Gra...
CVE-2026-41065HIGH8.9Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable t...
CVE-2026-36180MEDIUM4.6A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only pr...
CVE-2026-36178MEDIUM4.6The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configu...
CVE-2026-36176HIGH7.1GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial c...
CVE-2026-36175MEDIUM6.8An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and ...
CVE-2026-36174MEDIUM4.6GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations t...
CVE-2026-35906CRITICAL9.6An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated at...
CVE-2026-35905CRITICAL9.8T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded passw...
CVE-2026-35904CRITICAL9.8Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now