2026 CVE Vulnerabilities

67,120 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27857HIGH7.5Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi...
CVE-2026-27856MEDIUM5.9Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can u...
CVE-2026-27855MEDIUM5.9Dovecot OTP authentication is vulnerable to replay attack under specific conditions. If auth cache is enabled, and usern...
CVE-2026-24031HIGH8.2Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows...
CVE-2026-0394MEDIUM5.3When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s...
CVE-2026-4948MEDIUM5.5A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D...
CVE-2026-34353MEDIUM5.1In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when un...
CVE-2026-33559MEDIUM5.4WordPress Plugin "OpenStreetMap" provided by MiKa contains a cross-site scripting vulnerability. On the site with the af...
CVE-2026-33366MEDIUM6.9Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for...
CVE-2026-33280CRITICAL9.8Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the pr...
CVE-2026-32678HIGH8.7Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical confi...
CVE-2026-32669CRITICAL9.8Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary c...
CVE-2026-27650CRITICAL9.8OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbit...
CVE-2026-22744HIGH7.5In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value fo...
CVE-2026-22743HIGH7.5Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. Whe...
CVE-2026-22742HIGH8.6Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatMo...
CVE-2026-22738CRITICAL9.8In Spring AI, a SpEL injection vulnerability exists in SimpleVectorStore when a user-supplied value is used as a filter ...
CVE-2026-4910HIGH7.3A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an u...
CVE-2026-3098MEDIUM6.5The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1...
CVE-2026-4909LOW2.4A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /...
CVE-2026-4908CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the ...
CVE-2026-4907MEDIUM6.3A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted...
CVE-2026-4906HIGH8.8A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /gof...
CVE-2026-33935HIGH7.5MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att...
CVE-2026-33890CRITICAL9.8MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated att...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now