2026 CVE Vulnerabilities

67,429 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61833HIGH8.1zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior ...
CVE-2026-61795MEDIUM6.8Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnU...
CVE-2026-61794MEDIUM6.8Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update valida...
CVE-2026-61672HIGH7.1Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in p...
CVE-2026-61633LOW2NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supp...
CVE-2026-61548HIGH8.1Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseS...
CVE-2026-58197HIGH8.8ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too...
CVE-2026-55556HIGH8.2Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_aut...
CVE-2026-46655HIGH7.8virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits...
CVE-2026-44639LOW3.7NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c ...
CVE-2026-93737MEDIUM6.5Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticate...
CVE-2026-93736MEDIUM4.3Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated att...
CVE-2026-93690HIGH7.5uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely ...
CVE-2026-93689MEDIUM5.5WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device contro...
CVE-2026-93688HIGH7.5SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstra...
CVE-2026-93687HIGH7.5braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attack...
CVE-2026-93532MEDIUM6.3A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf7...
CVE-2026-93531MEDIUM4.3A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vu...
CVE-2026-88259HIGH7.5CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenti...
CVE-2026-86689MEDIUM5.9Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active ...
CVE-2026-86520HIGH7.5Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active ...
CVE-2026-84451MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of un...
CVE-2026-84450MEDIUM4.3libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a ...
CVE-2026-84449LOW3.7libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() ...
CVE-2026-84448MEDIUM4libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inli...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now