2026 CVE Vulnerabilities

48,334 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11425MEDIUM4.4Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo...
CVE-2026-71870MEDIUM4.8pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause large memory consumpti...
CVE-2026-66151MEDIUM5.5SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the ...
CVE-2026-65819HIGH7.5gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-con...
CVE-2026-62296HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11...
CVE-2026-62295HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11...
CVE-2026-62293MEDIUM5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11...
CVE-2026-61808CRITICAL9.8LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds t...
CVE-2026-48039CRITICAL9.1Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `A...
CVE-2026-48007HIGH8.6Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to ...
CVE-2026-47661HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-47660HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-47659HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-19243MEDIUM6.3A security vulnerability has been detected in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_comman...
CVE-2026-19113MEDIUM5.3Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of servic...
CVE-2026-19017MEDIUM6.8Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read whe...
CVE-2026-19016MEDIUM4.2Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission...
CVE-2026-19015MEDIUM5.3Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumptio...
CVE-2026-19014MEDIUM4.3Consul Community Edition and Consul Enterprise 1.17.0 through 2.0.2 are vulnerable to an uncontrolled resource consumpti...
CVE-2026-19012MEDIUM5.3Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service...
CVE-2026-15972HIGH7.5Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi...
CVE-2026-15970MEDIUM4.2Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypa...
CVE-2026-71852MEDIUM4.8pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and larg...
CVE-2026-71851CRITICAL9crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in Crypt...
CVE-2026-71850MEDIUM4.8Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now