2026 CVE Vulnerabilities

67,413 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23659HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disc...
CVE-2026-23658CRITICAL9.8Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-3580MEDIUM4.7In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by...
CVE-2026-3579MEDIUM5.9wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The...
CVE-2026-32238CRITICAL9.1OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2026-32119MEDIUM4.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-25928MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-25744MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-3503MEDIUM5.2Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi...
CVE-2026-25667HIGH7.5ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause ex...
CVE-2026-3548CRITICAL9.8Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer over...
CVE-2026-30694CRITICAL9.8An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter compone...
CVE-2026-2646HIGH8.1A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session ...
CVE-2026-2645HIGH7.5In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could ...
CVE-2026-26940MEDIUM6.5Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead De...
CVE-2026-26939MEDIUM6.5Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp...
CVE-2026-26933MEDIUM5.7Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser...
CVE-2026-30403HIGH7.5There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud ...
CVE-2026-26931MEDIUM5.7Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead...
CVE-2026-1005MEDIUM5.3Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryptio...
CVE-2026-0819HIGH7.1A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSign...
CVE-2026-3029HIGH7.5A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver...
CVE-2026-32869MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w...
CVE-2026-32868MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the ...
CVE-2026-32867CRITICAL9.8OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now