2026 CVE Vulnerabilities

49,039 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18973HIGH7.3A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz...
CVE-2026-67873CRITICAL9.8A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occ...
CVE-2026-67872HIGH7.5An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queu...
CVE-2026-67871HIGH7.5Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddN...
CVE-2026-67870CRITICAL9.8In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local E...
CVE-2026-67869HIGH7.5Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_...
CVE-2026-67531CRITICAL9.3FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:ex...
CVE-2026-52466CRITICAL9.8Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to sto...
CVE-2026-19028MEDIUM6.8H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the ...
CVE-2026-19027MEDIUM6.9The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H...
CVE-2026-18970HIGH7.3A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected elemen...
CVE-2026-18969HIGH7.3A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is ...
CVE-2026-18968MEDIUM4.3A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue...
CVE-2026-67867HIGH7.5Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alar...
CVE-2026-67866HIGH7.5Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Lock...
CVE-2026-67863HIGH7.5In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when ...
CVE-2026-19026MEDIUM6.8H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating th...
CVE-2026-19025MEDIUM6.8H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout d...
CVE-2026-19024HIGH8.2NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a d...
CVE-2026-19023MEDIUM6.8Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers...
CVE-2026-71321HIGH7.5Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren...
CVE-2026-71320HIGH8.1Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject ...
CVE-2026-71319CRITICAL9.6Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) expos...
CVE-2026-71318MEDIUM4.8Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply ...
CVE-2026-71316HIGH7.5Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now