2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5442CRITICAL9.8A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Represe...
CVE-2026-5441HIGH7.1An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1...
CVE-2026-5440HIGH7.5A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The se...
CVE-2026-5439HIGH7.5A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded...
CVE-2026-5438HIGH7.5A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The se...
CVE-2026-5437HIGH7.5An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malf...
CVE-2026-4116HIGH7.2Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user t...
CVE-2026-4114MEDIUM6.6Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin ...
CVE-2026-4113HIGH7.2An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to ...
CVE-2026-4112HIGH7.2Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series applian...
CVE-2026-34757MEDIUM4.4LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-34578HIGH8.2OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector pas...
CVE-2026-4660HIGH7.5HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operatio...
CVE-2026-3005MEDIUM6.4The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho...
CVE-2026-2519MEDIUM5.3The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation v...
CVE-2026-24661MEDIUM6.5Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which all...
CVE-2026-21388MEDIUM6.5Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which all...
CVE-2026-4901MEDIUM6.5AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker...
CVE-2026-34538MEDIUM6.5Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have ...
CVE-2026-34185HIGH8.8AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in pla...
CVE-2026-34184CRITICAL9.1AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all file...
CVE-2026-34179CRITICAL9.1In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate th...
CVE-2026-34178CRITICAL9.1In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supp...
CVE-2026-34177CRITICAL9.1Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limit...
CVE-2026-5854CRITICAL9.8A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEas...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now