2026 CVE Vulnerabilities

50,404 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71281HIGH8.8Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src...
CVE-2026-71280HIGH8.5go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien...
CVE-2026-71279HIGH8Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa...
CVE-2026-71278CRITICAL9.8rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont...
CVE-2026-71277CRITICAL9.1rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP ...
CVE-2026-71276HIGH7.1Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor...
CVE-2026-71275MEDIUM5.4OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r...
CVE-2026-71274HIGH8.5OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co...
CVE-2026-71273MEDIUM6.5OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w...
CVE-2026-71272HIGH8.5Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa...
CVE-2026-71271HIGH8.5Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDR...
CVE-2026-71270HIGH8.6Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanit...
CVE-2026-71269HIGH7.2Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-...
CVE-2026-71268CRITICAL9.9OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.s...
CVE-2026-71267CRITICAL9.8microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name...
CVE-2026-71266HIGH7.8tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a f...
CVE-2026-71265HIGH7.5Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data ...
CVE-2026-71264HIGH8.2WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike ...
CVE-2026-71263CRITICAL9.1The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). Th...
CVE-2026-71262CRITICAL9.8IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (...
CVE-2026-71261HIGH7.8dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. I...
CVE-2026-71260MEDIUM6.5ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho...
CVE-2026-71259HIGH8.6ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py...
CVE-2026-71227MEDIUM5.1A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO...
CVE-2026-71226HIGH7.3Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now