2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-18997MEDIUM6.3A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBg...
CVE-2026-18996MEDIUM6.3A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function P...
CVE-2026-18995MEDIUM4.3A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f...
CVE-2026-18993MEDIUM6.3A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functiona...
CVE-2026-18992MEDIUM6.3A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of ...
CVE-2026-18909MEDIUM5.6A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and...
CVE-2026-18980MEDIUM6.3A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the fi...
CVE-2026-18976MEDIUM6.3A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions...
CVE-2026-18974MEDIUM5.5A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the...
CVE-2026-19028MEDIUM6.8H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the ...
CVE-2026-19027MEDIUM6.9The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H...
CVE-2026-18968MEDIUM4.3A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue...
CVE-2026-19026MEDIUM6.8H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating th...
CVE-2026-19025MEDIUM6.8H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout d...
CVE-2026-19023MEDIUM6.8Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers...
CVE-2026-71318MEDIUM4.8Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply ...
CVE-2026-71313MEDIUM6.9rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51...
CVE-2026-71311MEDIUM6.4rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-71310MEDIUM5.9rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-18959MEDIUM5.4A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des...
CVE-2026-15996MEDIUM6.6A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to...
CVE-2026-70618MEDIUM5.3Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user ...
CVE-2026-66885MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b...
CVE-2026-21766MEDIUM5.4The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. ...
CVE-2026-18954MEDIUM5.7Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now