2026 CVE Vulnerabilities

49,856 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-19000HIGH7.3A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/...
CVE-2026-18998MEDIUM6.3A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of ...
CVE-2026-18997MEDIUM6.3A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBg...
CVE-2026-15459HIGH8.1The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
CVE-2026-18996MEDIUM6.3A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function P...
CVE-2026-18995MEDIUM4.3A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f...
CVE-2026-18993MEDIUM6.3A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functiona...
CVE-2026-18992MEDIUM6.3A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of ...
CVE-2026-18909MEDIUM5.6A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and...
CVE-2026-18325HIGH7.2The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-16636HIGH7.2The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for Wo...
CVE-2026-15991HIGH8.8The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation ...
CVE-2026-18991HIGH7.3A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file c...
CVE-2026-18990HIGH7.3A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts o...
CVE-2026-18980MEDIUM6.3A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the fi...
CVE-2026-18976MEDIUM6.3A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions...
CVE-2026-18974MEDIUM5.5A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the...
CVE-2026-18973HIGH7.3A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitiz...
CVE-2026-67873CRITICAL9.8A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occ...
CVE-2026-67872HIGH7.5An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queu...
CVE-2026-67871HIGH7.5Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddN...
CVE-2026-67870CRITICAL9.8In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local E...
CVE-2026-67869HIGH7.5Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_...
CVE-2026-67531CRITICAL9.3FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:ex...
CVE-2026-52466CRITICAL9.8Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to sto...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now