2026 CVE Vulnerabilities

48,306 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46405MEDIUM5.3OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth m...
CVE-2026-45808HIGH7.1OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide...
CVE-2026-11743MEDIUM6.6The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o...
CVE-2026-11742LOW3.6The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read...
CVE-2026-9031MEDIUM6.8An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da...
CVE-2026-9030MEDIUM6.8A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction han...
CVE-2026-71381MEDIUM4Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could r...
CVE-2026-70624Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-70623Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-69207MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in COR...
CVE-2026-66061HIGH7.1Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS...
CVE-2026-66060HIGH7.1Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co...
CVE-2026-59717MEDIUM4.3Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr...
CVE-2026-54338MEDIUM5.3JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid in...
CVE-2026-50540CRITICAL9.6Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-47664HIGH8.6Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-47663HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-47662HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-46358MEDIUM5.4OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functi...
CVE-2026-19246MEDIUM6.3A vulnerability has been found in HKUDS nanobot up to 0.2.1. This affects the function _download_image_data_url of the f...
CVE-2026-19245LOW3.3A flaw has been found in HKUDS nanobot up to 0.2.1. The impacted element is the function ExecTool._prepare_command of th...
CVE-2026-19244MEDIUM4.7A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of t...
CVE-2026-11425MEDIUM4.4Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo...
CVE-2026-71870MEDIUM4.8pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumpti...
CVE-2026-66151MEDIUM5.5SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now