2026 CVE Vulnerabilities

50,944 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15830MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome...
CVE-2026-15337MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()...
CVE-2026-15314HIGH7.5Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT...
CVE-2026-15307HIGH8.8An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse...
CVE-2026-69254CRITICAL9.4Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScri...
CVE-2026-69253CRITICAL9Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1...
CVE-2026-69252HIGH7.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/fil...
CVE-2026-69110CRITICAL9.3OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attacker...
CVE-2026-69100HIGH8.8LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i...
CVE-2026-69098CRITICAL9.8kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows ...
CVE-2026-25292HIGH7.6Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration...
CVE-2026-25289CRITICAL9.6Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with inv...
CVE-2026-25288HIGH7.4Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
CVE-2026-24084HIGH7.5Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed cap...
CVE-2026-24083HIGH7.8Memory Corruption while processing IOCTL device driver requests with invalid arguments.
CVE-2026-24080HIGH7.8Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079HIGH8.1Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
CVE-2026-24078MEDIUM6.5Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077MEDIUM6.5Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel...
CVE-2026-24076MEDIUM6.7Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21366HIGH7.8Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-18801CRITICAL9.3OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution ...
CVE-2026-18773MEDIUM6.3A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_...
CVE-2026-10032MEDIUM6.1The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U...
CVE-2026-69251CRITICAL9Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now