2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33361HIGH7.5In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), a...
CVE-2026-33359HIGH7.5In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion s...
CVE-2026-33357HIGH7.5In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and...
CVE-2026-33356HIGH7.7In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to gl...
CVE-2026-31254HIGH7.3The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection ...
CVE-2026-31253HIGH7.3The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an ins...
CVE-2026-31252MEDIUM5.7CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera...
CVE-2026-31251HIGH7.3CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera...
CVE-2026-31250HIGH7.3CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera...
CVE-2026-31249HIGH7.3CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera...
CVE-2026-31248HIGH7.5Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and val...
CVE-2026-8292MEDIUM6.5A security vulnerability has been detected in Open5GS up to 2.7.7. The affected element is the function yuarel_parse in ...
CVE-2026-8291MEDIUM6.5A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the fi...
CVE-2026-7820MEDIUM6.9Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS o...
CVE-2026-7819HIGH8.1Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, ...
CVE-2026-7818HIGH7.8Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe...
CVE-2026-7817HIGH7.1Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration end...
CVE-2026-7816HIGH8.8OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolat...
CVE-2026-7815HIGH8.8SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_p...
CVE-2026-7814MEDIUM4.8Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controll...
CVE-2026-7813CRITICAL9.9Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Proces...
CVE-2026-6815MEDIUM5.9An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path s...
CVE-2026-6093MEDIUM6Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose record...
CVE-2026-44643CRITICAL10Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an att...
CVE-2026-44201MEDIUM5.3Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and I...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now