2026 CVE Vulnerabilities

50,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71286MEDIUM6.1The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property...
CVE-2026-71285HIGH8.1Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo ...
CVE-2026-71284HIGH7.2Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir...
CVE-2026-71283MEDIUM4.9Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile...
CVE-2026-71282MEDIUM6.5ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol...
CVE-2026-71281HIGH8.8Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src...
CVE-2026-71280HIGH8.5go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Clien...
CVE-2026-71279HIGH8Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT messa...
CVE-2026-71278CRITICAL9.8rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) cont...
CVE-2026-71277CRITICAL9.1rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP ...
CVE-2026-71276HIGH7.1Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transpor...
CVE-2026-71275MEDIUM5.4OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r...
CVE-2026-71274HIGH8.5OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel co...
CVE-2026-71273MEDIUM6.5OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w...
CVE-2026-71272HIGH8.5Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.Defa...
CVE-2026-71271HIGH8.5Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDR...
CVE-2026-71270HIGH8.6Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanit...
CVE-2026-71269HIGH7.2Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-...
CVE-2026-71268CRITICAL9.9OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.s...
CVE-2026-71267CRITICAL9.8microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name...
CVE-2026-71266HIGH7.8tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a f...
CVE-2026-71265HIGH7.5Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data ...
CVE-2026-71264HIGH8.2WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike ...
CVE-2026-71263CRITICAL9.1The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). Th...
CVE-2026-71262CRITICAL9.8IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now