2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5977CRITICAL9.8A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of th...
CVE-2026-5447HIGH7.5Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when conve...
CVE-2026-5446HIGH7.1In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every applicati...
CVE-2026-40109LOW3.1Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prio...
CVE-2026-40107MEDIUM6.5SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loos...
CVE-2026-40093HIGH8.1nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestam...
CVE-2026-35206MEDIUM4.4Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart wi...
CVE-2026-5976CRITICAL9.8A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of...
CVE-2026-5975CRITICAL9.8A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg ...
CVE-2026-5974CRITICAL9.8A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in...
CVE-2026-5973CRITICAL9.8A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file me...
CVE-2026-5972CRITICAL9.8A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_com...
CVE-2026-5194CRITICAL9.1Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller...
CVE-2026-5187CRITICAL9.8Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds che...
CVE-2026-4436HIGH8.6A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant i...
CVE-2026-40089CRITICAL9.9Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack da...
CVE-2026-40088CRITICAL9.6PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are...
CVE-2026-40087MEDIUM5.3LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-str...
CVE-2026-40077LOW3.1Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied sys...
CVE-2026-39977MEDIUM6.3flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key take...
CVE-2026-35577HIGH8.1Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7....
CVE-2026-35063HIGH8.8OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with r...
CVE-2026-34734HIGH7.8HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utilit...
CVE-2026-34500MEDIUM6.5CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Ap...
CVE-2026-34487HIGH7.5Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apach...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now