2026 CVE Vulnerabilities

66,671 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5312MEDIUM5.5A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D...
CVE-2026-4820MEDIUM4.3IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or sessi...
CVE-2026-4364MEDIUM5.4IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-4101CRITICAL9.8IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-34873CRITICAL9.1An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session...
CVE-2026-34545HIGH7.3OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34544HIGH7.3OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34543HIGH7.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34531HIGH8.2Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situa...
CVE-2026-34530MEDIUM6.9File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-34529CRITICAL9File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-34528CRITICAL9.8File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-34525MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host h...
CVE-2026-34520CRITICAL9.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (t...
CVE-2026-34519MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who...
CVE-2026-34518MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following ...
CVE-2026-34517MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multip...
CVE-2026-34516HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with...
CVE-2026-34515HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the ...
CVE-2026-34514MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who...
CVE-2026-34513HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DN...
CVE-2026-2862MEDIUM5.3IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-2475MEDIUM4.7IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-22815HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient re...
CVE-2026-1491MEDIUM5.3IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now