2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6330MEDIUM6.5The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's i...
CVE-2026-6329MEDIUM6.5PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and all...
CVE-2026-6092MEDIUM5.3When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing E...
CVE-2026-55962MEDIUM6.5TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the cl...
CVE-2026-44622MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-13282MEDIUM6.8Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially e...
CVE-2026-10098MEDIUM5.3OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose se...
CVE-2026-6681MEDIUM5.3The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written...
CVE-2026-6678MEDIUM5.3Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handlin...
CVE-2026-6450MEDIUM5.3A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allow...
CVE-2026-6412MEDIUM4.3Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate proce...
CVE-2026-57522MEDIUM5Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens()...
CVE-2026-57521MEDIUM5.3Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to ac...
CVE-2026-55964MEDIUM5.3Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to ha...
CVE-2026-2299MEDIUM4.3The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoi...
CVE-2026-10592MEDIUM5.3Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildca...
CVE-2026-56779MEDIUM6.4MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allo...
CVE-2026-56774MEDIUM5.4Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id par...
CVE-2026-56772MEDIUM5.3NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private no...
CVE-2026-54250MEDIUM5.8K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a ...
CVE-2026-54093MEDIUM6.8File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-54092MEDIUM6.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-46611MEDIUM5.3Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s,...
CVE-2026-28898MEDIUM5.3swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing t...
CVE-2026-6291MEDIUM6.5Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now