2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-37539CRITICAL9.8Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and dec...
CVE-2026-37538HIGH7.5Buffer overflow vulnerability in socketcand 0.4.2 in file socketcand.c in function main allows attackers to cause a deni...
CVE-2026-37537HIGH8.1collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow ...
CVE-2026-37536HIGH8.8miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diag...
CVE-2026-37535HIGH7.1openxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6f5d46ac (2021-08-09) contains an out-of-bounds read in the I...
CVE-2026-37534CRITICAL9.8Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in S...
CVE-2026-37532HIGH7.1AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_re...
CVE-2026-37531CRITICAL9.8AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU rac...
CVE-2026-37530HIGH7.5AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_re...
CVE-2026-37526HIGH7.8AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision comman...
CVE-2026-37525HIGH7.8AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision ...
CVE-2026-7586MEDIUM4.3A weakness has been identified in Open5GS up to 2.7.7. Affected is the function ogs_id_get_value of the file /src/amf/nu...
CVE-2026-7585MEDIUM4.3A vulnerability was determined in Open5GS up to 2.7.7. The impacted element is the function amf_nudm_sdm_handle_provisio...
CVE-2026-42481MEDIUM5.5Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can b...
CVE-2026-42480MEDIUM5.5A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology...
CVE-2026-42475MEDIUM6.5SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHe...
CVE-2026-42474MEDIUM6.5SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `data` array to the data function in BuildHe...
CVE-2026-42473CRITICAL9.8Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize...
CVE-2026-42472CRITICAL9.8Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize...
CVE-2026-42471HIGH8.1Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) cal...
CVE-2026-37554HIGH7.5An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The v...
CVE-2026-37552HIGH8.4Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) rec...
CVE-2026-37505MEDIUM4.9SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort para...
CVE-2026-37504HIGH7.5Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyControlle...
CVE-2026-37503MEDIUM4.8Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now