2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1871MEDIUM6.5TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validat...
CVE-2026-10606HIGH7.3A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedbac...
CVE-2026-0611CRITICAL9.8Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code...
CVE-2026-9590MEDIUM5.3Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an aut...
CVE-2026-9522MEDIUM5.4Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authe...
CVE-2026-7299MEDIUM5.4Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them i...
CVE-2026-49754HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2...
CVE-2026-49753MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allow...
CVE-2026-48862HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2...
CVE-2026-48861LOW2.1Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Split...
CVE-2026-47117CRITICAL9.8OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The pr...
CVE-2026-45686HIGH7.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0...
CVE-2026-45685HIGH7.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0...
CVE-2026-45684MEDIUM5.3OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0...
CVE-2026-45683LOW3.8OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45682MEDIUM5.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45681MEDIUM5.9OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45680HIGH7.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45679MEDIUM6.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45678HIGH7.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45676MEDIUM5.5OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0...
CVE-2026-45554MEDIUM5.3NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static asse...
CVE-2026-45553HIGH7.5NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-...
CVE-2026-45080MEDIUM6.9Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access co...
CVE-2026-44367LOW2.7Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability ex...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now