2026 CVE Vulnerabilities

66,705 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34517MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multip...
CVE-2026-34516HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, a response with...
CVE-2026-34515HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the ...
CVE-2026-34514MEDIUM5.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who...
CVE-2026-34513HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DN...
CVE-2026-2862MEDIUM5.3IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-2475MEDIUM4.7IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-22815HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient re...
CVE-2026-1491MEDIUM5.3IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-1345HIGH7.3IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-5311MEDIUM5.5A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-32...
CVE-2026-34872CRITICAL9.1An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory...
CVE-2026-34750MEDIUM6.5Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azu...
CVE-2026-34749MEDIUM5.4Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forg...
CVE-2026-34748HIGH8.7Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/next, a sto...
CVE-2026-34747HIGH8.2Payload is a free and open source headless content management system. Prior to version 3.79.1, certain request inputs we...
CVE-2026-34746HIGH7.7Payload is a free and open source headless content management system. Prior to version 3.79.1, an authenticated Server-S...
CVE-2026-34456CRITICAL9.8Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From ver...
CVE-2026-34455HIGH8.8Hi.Events is an open-source event management and ticket selling platform. From version 0.8.0-beta.1 to before version 1....
CVE-2026-35000HIGH7.1ChangeDetection.io versions prior to 0.54.7 contain a protection bypass vulnerability in the SafeXPath3Parser implementa...
CVE-2026-34874HIGH7.5An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distingu...
CVE-2026-34871MEDIUM6.7An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predict...
CVE-2026-25835HIGH7.7Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG).
CVE-2026-25833HIGH7.5Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function
CVE-2026-5199LOW2.3A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a vict...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now