2026 CVE Vulnerabilities

68,105 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3503MEDIUM5.2Protection mechanism failure in wolfCrypt post-quantum implementations (ML-KEM and ML-DSA) in wolfSSL on ARM Cortex-M mi...
CVE-2026-25667HIGH7.5ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause ex...
CVE-2026-3548CRITICAL9.8Two buffer overflow vulnerabilities existed in the wolfSSL CRL parser when parsing CRL numbers: a heap-based buffer over...
CVE-2026-30694CRITICAL9.8An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter compone...
CVE-2026-2646HIGH8.1A heap-buffer-overflow vulnerability exists in wolfSSL's wolfSSL_d2i_SSL_SESSION() function. When deserializing session ...
CVE-2026-2645HIGH7.5In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could ...
CVE-2026-26940MEDIUM6.5Improper Validation of Specified Quantity in Input (CWE-1284) in the Timelion visualization plugin in Kibana can lead De...
CVE-2026-26939MEDIUM6.5Missing Authorization (CWE-862) in Kibana’s server-side Detection Rule Management can lead to Unauthorized Endpoint Resp...
CVE-2026-26933MEDIUM5.7Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Ser...
CVE-2026-30403HIGH7.5There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud ...
CVE-2026-26931MEDIUM5.7Memory Allocation with Excessive Size Value (CWE-789) in the Prometheus remote_write HTTP handler in Metricbeat can lead...
CVE-2026-1005MEDIUM5.3Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryptio...
CVE-2026-0819HIGH7.1A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSign...
CVE-2026-3029HIGH7.5A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF ver...
CVE-2026-32869MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of the "Name of Organization" field w...
CVE-2026-32868MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in the ...
CVE-2026-32867CRITICAL9.8OPEXUS eComplaint before version 10.1.0.0 allows an unauthenticated attacker to obtain or guess an existing case number ...
CVE-2026-32866MEDIUM5.4OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a us...
CVE-2026-32865CRITICAL9.8OPEXUS eComplaint and eCASE before version 10.1.0.0 include the secret verification code in the HTTP response when reque...
CVE-2026-30404HIGH7.5The backend database management connection test feature in wgcloud v3.6.3 has a server-side request forgery (SSRF) vulne...
CVE-2026-4427——Rejected reason: Duplicate of CVE-2026-32286
CVE-2026-4426MEDIUM6.5A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by ...
CVE-2026-4424HIGH7.5A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic du...
CVE-2026-32843MEDIUM5.1Location Aware Sensor System by Linkit ONE, up to commit f06bd20 (2023-04-26), contains a reflected cross-site scripting...
CVE-2026-30711HIGH8.8Devome GRR v4.5.0 was discovered to contain multiple authenticated SQL injection vulnerabilities in the include/session....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now