2026 CVE Vulnerabilities

48,064 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48933HIGH7.5A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2Gi...
CVE-2026-48619HIGH7.5A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out...
CVE-2026-48615HIGH7.5A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. Wh...
CVE-2026-9221HIGH8.7The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request si...
CVE-2026-9220HIGH8.7Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and i...
CVE-2026-9219HIGH8.3Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derive...
CVE-2026-40083HIGH7.2Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through...
CVE-2026-8720HIGH7.5wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a ...
CVE-2026-7532HIGH7.5iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced ...
CVE-2026-7511HIGH7.5PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bo...
CVE-2026-6331HIGH7.5HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC ve...
CVE-2026-6325HIGH7.5Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write pas...
CVE-2026-54479HIGH7.3The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-50176HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-22879HIGH8.1vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability
CVE-2026-13283HIGH7.5Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a...
CVE-2026-13281HIGH8.3Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the rend...
CVE-2026-12992HIGH7.4A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.ws...
CVE-2026-12975HIGH8.5A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without ena...
CVE-2026-11800HIGH8.1A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an a...
CVE-2026-11703HIGH7.5Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for t...
CVE-2026-6731HIGH7.5X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN...
CVE-2026-6679HIGH7.5A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. T...
CVE-2026-38640HIGH7.5A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a De...
CVE-2026-38637HIGH7.5An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of S...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now