2026 CVE Vulnerabilities

67,222 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-88344HIGH7.5An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers sche...
CVE-2026-88341MEDIUM5.5A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can ...
CVE-2026-88340HIGH7.6An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vu...
CVE-2026-88339MEDIUM5.5A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). T...
CVE-2026-87121CRITICAL9.8lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution ...
CVE-2026-83805MEDIUM6.4Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkf...
CVE-2026-83801MEDIUM5.4Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add...
CVE-2026-79767MEDIUM5.5Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143....
CVE-2026-77322HIGH7.5SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go...
CVE-2026-76717MEDIUM5.3A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive inf...
CVE-2026-76716MEDIUM5.3Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or deni...
CVE-2026-76715HIGH7.1A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-midd...
CVE-2026-76714HIGH7.2Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary co...
CVE-2026-76713HIGH7.2A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful explo...
CVE-2026-76712HIGH7.3A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information di...
CVE-2026-76711HIGH7.5A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly process...
CVE-2026-76710HIGH7.5A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure...
CVE-2026-76709CRITICAL9.8A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful explo...
CVE-2026-76708CRITICAL9.8A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system ...
CVE-2026-75432MEDIUM5.1An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::Po...
CVE-2026-65829MEDIUM5.3MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 ...
CVE-2026-63628MEDIUM6.9mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/...
CVE-2026-63627MEDIUM6.9mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-p...
CVE-2026-63104HIGH8.1Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace me...
CVE-2026-62985HIGH7.5request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now