2026 CVE Vulnerabilities

61,786 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45286MEDIUM4.3Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6...
CVE-2026-45285MEDIUM6.4Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before ...
CVE-2026-45284HIGH8.8Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper chec...
CVE-2026-45283MEDIUM4.3Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, a...
CVE-2026-45282MEDIUM6.5Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-45281HIGH8.1Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-45279MEDIUM6.5Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, ...
CVE-2026-45278MEDIUM6.1Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can ...
CVE-2026-45277LOW3.3Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arb...
CVE-2026-45275MEDIUM6.5Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability...
CVE-2026-43958HIGH7.8A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a ...
CVE-2026-43625HIGH8.2CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo...
CVE-2026-43624HIGH8.8F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauth...
CVE-2026-43623HIGH8.8microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/micro...
CVE-2026-41013HIGH8.1Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF s...
CVE-2026-40990MEDIUM6.5OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc...
CVE-2026-40989MEDIUM6.5Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi...
CVE-2026-37235HIGH7.5FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. T...
CVE-2026-37233HIGH7.5FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ri...
CVE-2026-37232HIGH8.6An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric...
CVE-2026-37231HIGH7.5FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,...
CVE-2026-37230HIGH7.5FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in ...
CVE-2026-37229HIGH7.5FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote una...
CVE-2026-37228HIGH7.5FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a f...
CVE-2026-37226HIGH7.5FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now