2026 CVE Vulnerabilities

50,680 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71226HIGH7.3Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm...
CVE-2026-71225MEDIUM6.5A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat...
CVE-2026-16022HIGH7.8@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constr...
CVE-2026-0516MEDIUM6.5A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to...
CVE-2026-71256CRITICAL9.8nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden...
CVE-2026-71255HIGH8.6nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res...
CVE-2026-71254CRITICAL9.8nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F...
CVE-2026-64582HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap ...
CVE-2026-61891HIGH7.5In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin...
CVE-2026-46581HIGH7.5In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or ...
CVE-2026-18933HIGH7.2The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri...
CVE-2026-71252HIGH8.2toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, ...
CVE-2026-71251MEDIUM6.5Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download...
CVE-2026-71250MEDIUM4.3Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex...
CVE-2026-71249MEDIUM6.1299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, f...
CVE-2026-71248CRITICAL9.8Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P...
CVE-2026-71247MEDIUM6.5Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t...
CVE-2026-71246MEDIUM4.3Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s...
CVE-2026-71245Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-71244MEDIUM6.5Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r...
CVE-2026-71243HIGH8.8The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest...
CVE-2026-71242HIGH8.3Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership ...
CVE-2026-71241HIGH7.5Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are mi...
CVE-2026-71240MEDIUM4.3DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or sta...
CVE-2026-71239HIGH8.1DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template const...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now