2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-86553HIGH8.8SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Us...
CVE-2026-86552MEDIUM5.4SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acqui...
CVE-2026-93959HIGH7.3A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown ...
CVE-2026-94084CRITICAL9.4Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.r...
CVE-2026-94083CRITICAL9.4Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state...
CVE-2026-93958CRITICAL9.1A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/...
CVE-2026-93957MEDIUM4.3A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleF...
CVE-2026-86551LOW3.3The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address ...
CVE-2026-94057MEDIUM5.3Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead dep...
CVE-2026-94056HIGH7.5Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uni...
CVE-2026-94055MEDIUM5.3Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
CVE-2026-94054MEDIUM5.3Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
CVE-2026-93993HIGH8.8Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes...
CVE-2026-93992HIGH8.1Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write...
CVE-2026-93991HIGH7.7Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that ...
CVE-2026-93990HIGH7.5Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malf...
CVE-2026-93989MEDIUM4.3vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in Sa...
CVE-2026-93988MEDIUM6.5QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows a...
CVE-2026-93956LOW3.5A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighl...
CVE-2026-93955MEDIUM4.3A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the functio...
CVE-2026-89155——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-93954MEDIUM4.3A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSet...
CVE-2026-82672MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allow...
CVE-2026-82560HIGH7.5Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting d...
CVE-2026-94001MEDIUM6.5A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now