2026 CVE Vulnerabilities

65,524 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5448MEDIUM4.3X.509 date buffer overflow in wolfSSL_X509_notAfter / wolfSSL_X509_notBefore. A buffer overflow may occur when parsing d...
CVE-2026-5393CRITICAL9.1Dual-Algorithm CertificateVerify out-of-bounds read. When processing a dual-algorithm CertificateVerify message, an out-...
CVE-2026-5392MEDIUM5.4Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the heap. The missing bound...
CVE-2026-5988HIGH8.8A vulnerability was detected in Tenda F451 1.0.0.7. This impacts the function formWrlsafeset of the file /goform/AdvSetW...
CVE-2026-5987MEDIUM4.7A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the function AbstractFree...
CVE-2026-5986MEDIUM5.5A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the ...
CVE-2026-5985HIGH7.3A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown ...
CVE-2026-5507MEDIUM4When restoring a session from cache, a pointer from the serialized session data is used in a free operation without vali...
CVE-2026-5504MEDIUM5.3A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repe...
CVE-2026-5503CRITICAL9.1In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This ...
CVE-2026-5295HIGH8A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/...
CVE-2026-34424CRITICAL9.8Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected throu...
CVE-2026-5984HIGH8.8A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formS...
CVE-2026-5983HIGH8.8A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /gofo...
CVE-2026-5982HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file...
CVE-2026-5981HIGH8.8A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform...
CVE-2026-5778MEDIUM6.5Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption ...
CVE-2026-5772MEDIUM5.3A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname...
CVE-2026-5264CRITICAL9.8Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that ...
CVE-2026-5263MEDIUM6.5URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification ...
CVE-2026-40154CRITICAL9.6PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted e...
CVE-2026-40153MEDIUM6.5PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os...
CVE-2026-40152MEDIUM5.3PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directo...
CVE-2026-40151MEDIUM5.3PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents end...
CVE-2026-40150MEDIUM6.5PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now