2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-2378MEDIUM6.5ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content bein...
CVE-2026-23536HIGH7.5A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated r...
CVE-2026-33179MEDIUM5.5libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a NULL pointer ...
CVE-2026-33165MEDIUM5libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream ca...
CVE-2026-33164HIGH7.5libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL u...
CVE-2026-33156HIGH7.8ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading ...
CVE-2026-33155HIGH7.5DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6...
CVE-2026-33154HIGH8.1dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side T...
CVE-2026-33151HIGH7.5Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3....
CVE-2026-33150HIGH7.8libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-fre...
CVE-2026-33147HIGH7.8GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions ...
CVE-2026-33144HIGH7.8GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability...
CVE-2026-33143HIGH7.5OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook...
CVE-2026-33142HIGH8.1OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-3230...
CVE-2026-4505MEDIUM6.3A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh...
CVE-2026-4504HIGH7.3A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/ed...
CVE-2026-4500MEDIUM6.3A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the fil...
CVE-2026-4499CRITICAL9.8A vulnerability was determined in D-Link DIR-820LW 2.03. Affected is the function ssdpcgi_main of the component SSDP. Ex...
CVE-2026-4438MEDIUM5.4Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the...
CVE-2026-4437HIGH7.5Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the...
CVE-2026-33140MEDIUM6.1PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS...
CVE-2026-33139HIGH7.8PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS...
CVE-2026-33126MEDIUM4.3Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Prior to version 0.16.3, ...
CVE-2026-4497CRITICAL9.8A vulnerability was determined in Totolink WA300 5.2cu.7112_B20190227. Affected by this issue is the function recvUpgrad...
CVE-2026-4496MEDIUM5.3A vulnerability was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880. Affected by this vul...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now