2026 CVE Vulnerabilities

49,221 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19024HIGH8.2NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a d...
CVE-2026-19023MEDIUM6.8Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers...
CVE-2026-71321HIGH7.5Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren...
CVE-2026-71320HIGH8.1Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject ...
CVE-2026-71319CRITICAL9.6Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) expos...
CVE-2026-71318MEDIUM4.8Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply ...
CVE-2026-71316HIGH7.5Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries ...
CVE-2026-67865HIGH7.5S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denia...
CVE-2026-67864HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement ty...
CVE-2026-71315HIGH8.2Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules ...
CVE-2026-71314HIGH7.5Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta...
CVE-2026-71313MEDIUM6.9rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51...
CVE-2026-71312HIGH8rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v...
CVE-2026-71311MEDIUM6.4rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-71310MEDIUM5.9rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-71309HIGH8.6rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40....
CVE-2026-34966HIGH8.3Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass...
CVE-2026-18959MEDIUM5.4A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des...
CVE-2026-18839LOW2.2An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal ...
CVE-2026-18411HIGH8.1The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k...
CVE-2026-17583HIGH8.4The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be ed...
CVE-2026-15996HIGH7.5A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to...
CVE-2026-70618MEDIUM5.3Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user ...
CVE-2026-70617HIGH8.6Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attac...
CVE-2026-70616HIGH7.1boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now