2026 CVE Vulnerabilities

50,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71261HIGH7.8dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. I...
CVE-2026-71260MEDIUM6.5ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho...
CVE-2026-71259HIGH8.6ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py...
CVE-2026-71227MEDIUM5.1A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO...
CVE-2026-71226HIGH7.3Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all subm...
CVE-2026-71225MEDIUM6.5A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat...
CVE-2026-16022HIGH7.8@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constr...
CVE-2026-0516MEDIUM6.5A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to...
CVE-2026-71256CRITICAL9.8nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_iden...
CVE-2026-71255HIGH8.6nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res...
CVE-2026-71254CRITICAL9.8nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (F...
CVE-2026-64582HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap ...
CVE-2026-61891HIGH7.5In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin...
CVE-2026-46581HIGH7.5In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or ...
CVE-2026-18933HIGH7.2The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-pri...
CVE-2026-71252HIGH8.2toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, ...
CVE-2026-71251MEDIUM6.5Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download...
CVE-2026-71250MEDIUM4.3Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an ex...
CVE-2026-71249MEDIUM6.1299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, f...
CVE-2026-71248CRITICAL9.8Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw P...
CVE-2026-71247MEDIUM6.5Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t...
CVE-2026-71246MEDIUM4.3Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it s...
CVE-2026-71245Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-71244MEDIUM6.5Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r...
CVE-2026-71243HIGH8.8The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, dest...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now