2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7403MEDIUM5.5A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the fil...
CVE-2026-1858MEDIUM4.8wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromis...
CVE-2026-7426HIGH8.1Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V...
CVE-2026-7425MEDIUM6.5Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4....
CVE-2026-7401MEDIUM4.3A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulne...
CVE-2026-7400HIGH7.3A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is...
CVE-2026-34965HIGH8.8Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection en...
CVE-2026-7466HIGH8.8AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline file...
CVE-2026-7439MEDIUM4.8AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without...
CVE-2026-7424HIGH8.1Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent netwo...
CVE-2026-7423MEDIUM6.5Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adj...
CVE-2026-7422HIGH7.1Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass ...
CVE-2026-7398HIGH7.3A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulne...
CVE-2026-7397MEDIUM4.4A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path ...
CVE-2026-41499MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo...
CVE-2026-30893CRITICAL9.9Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to befo...
CVE-2026-28221HIGH8.2Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to befo...
CVE-2026-27105HIGH7.1Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link...
CVE-2026-26206MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo...
CVE-2026-7396MEDIUM5.5A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality ...
CVE-2026-7394MEDIUM4.7A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unkn...
CVE-2026-5712HIGH8.8This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assi...
CVE-2026-26204MEDIUM5.5Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to befo...
CVE-2026-26015CRITICAL9.8DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing bot...
CVE-2026-7393MEDIUM4.7A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now