2026 CVE Vulnerabilities

67,186 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29044MEDIUM6.5EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the...
CVE-2026-27828HIGH7.5EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2...
CVE-2026-27816CRITICAL9.1EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_tra...
CVE-2026-27815CRITICAL9.1EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_session_setup cop...
CVE-2026-27814MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race (C++ UB) triggered by an A 1-phas...
CVE-2026-27813MEDIUM5.3EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This i...
CVE-2026-26074HIGH7EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std...
CVE-2026-26073MEDIUM5.9EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::queue`/...
CVE-2026-4897MEDIUM5.5A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to th...
CVE-2026-33397MEDIUM6.1The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-ne...
CVE-2026-30162MEDIUM6.1Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.
CVE-2026-29976MEDIUM6.2Buffer Overflow vulnerability in ZerBea hcxpcapngtool v. 7.0.1-43-g2ee308e allows a local attacker to obtain sensitive i...
CVE-2026-29934MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to ...
CVE-2026-29933MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the /index/login.html component of YZMCMS v7.4 allows attackers ...
CVE-2026-28298HIGH8.1SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when...
CVE-2026-28297HIGH8.7SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when...
CVE-2026-27664HIGH8.7A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base syst...
CVE-2026-27663HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base ...
CVE-2026-26072MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona...
CVE-2026-26071MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::string` concurre...
CVE-2026-26070MEDIUM4.2EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to `std::map<std::optiona...
CVE-2026-26008HIGH7.5EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that le...
CVE-2026-23995HIGH7.8EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initi...
CVE-2026-22790HIGH8.8EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` afte...
CVE-2026-22593HIGH7.8EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now