2026 CVE Vulnerabilities

64,935 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6968MEDIUM6.5Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated si...
CVE-2026-6967MEDIUM6.5Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 ...
CVE-2026-6966MEDIUM6.5Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v...
CVE-2026-41503HIGH7.5BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea...
CVE-2026-41502HIGH7.5BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of...
CVE-2026-41477HIGH7.8Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and ex...
CVE-2026-41476HIGH8.8Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's c...
CVE-2026-41475CRITICAL9.1BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea...
CVE-2026-41433HIGH8.4OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to befo...
CVE-2026-41429HIGH8.8arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr...
CVE-2026-41428CRITICAL9.1Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expr...
CVE-2026-41427MEDIUM6.5Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option d...
CVE-2026-41426MEDIUM6.1pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered e...
CVE-2026-41425MEDIUM5.4Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection ...
CVE-2026-41244MEDIUM4.7Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the Ci...
CVE-2026-41907HIGH7.5uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buf...
CVE-2026-41894HIGH7.1SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a d...
CVE-2026-41492CRITICAL9.8Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through...
CVE-2026-41421HIGH8.8SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messa...
CVE-2026-41419HIGH7.64ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an ...
CVE-2026-41418MEDIUM5.34ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumerat...
CVE-2026-41416HIGH7.5PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer ...
CVE-2026-41415CRITICAL9.1PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-b...
CVE-2026-41414HIGH7.4Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.ym...
CVE-2026-41328CRITICAL9.1Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now