2026 CVE Vulnerabilities

61,770 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10804MEDIUM4.7A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/r...
CVE-2026-10803LOW3.6A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflo...
CVE-2026-10802MEDIUM4.3A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the libra...
CVE-2026-49077MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMembe...
CVE-2026-10801LOW3.6A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_...
CVE-2026-8916MEDIUM6.1Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: b...
CVE-2026-50226MEDIUM5.3Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrar...
CVE-2026-50225CRITICAL9.1The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t...
CVE-2026-50224MEDIUM4.9The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l...
CVE-2026-50214CRITICAL9.8The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary...
CVE-2026-4881MEDIUM6.5In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being...
CVE-2026-49771HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Galler...
CVE-2026-49510MEDIUM6.1Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects ...
CVE-2026-47320MEDIUM6.1Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Mani...
CVE-2026-47319MEDIUM6.1Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. T...
CVE-2026-47318MEDIUM6.1Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rl...
CVE-2026-47306MEDIUM6.1Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This iss...
CVE-2026-10800LOW3.6A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_featu...
CVE-2026-10305MEDIUM6.1Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: be...
CVE-2026-50213HIGH7.5The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled b...
CVE-2026-50212MEDIUM6.5Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user...
CVE-2026-50211CRITICAL9.8Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious...
CVE-2026-50210HIGH7.5The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to re...
CVE-2026-50209HIGH7.8Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres...
CVE-2026-50208CRITICAL9.4High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now