2026 CVE Vulnerabilities

50,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-24078MEDIUM6.5Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
CVE-2026-24077MEDIUM6.5Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel...
CVE-2026-24076MEDIUM6.7Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21366HIGH7.8Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-18801CRITICAL9.3OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution ...
CVE-2026-18773MEDIUM6.3A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_...
CVE-2026-10032MEDIUM6.1The openUrl function in @a2ui/web_core passes an agent-controlled URL directly to window.open() without validating the U...
CVE-2026-69251CRITICAL9Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record ...
CVE-2026-69250HIGH8.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 toke...
CVE-2026-68494HIGH8.7The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401 (GHSA-72hv-8253-57qq, number length constraint byp...
CVE-2026-67618MEDIUM6.5marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat...
CVE-2026-67200HIGH8.7Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary...
CVE-2026-67199HIGH7.1Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop...
CVE-2026-67198HIGH8.7Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauth...
CVE-2026-67196MEDIUM5.4Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in...
CVE-2026-67195HIGH8.8Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitr...
CVE-2026-61515CRITICAL9.8Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allo...
CVE-2026-61514CRITICAL9.8Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthent...
CVE-2026-18770HIGH7.3A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an un...
CVE-2026-18766MEDIUM6.3A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affect...
CVE-2026-18650HIGH8.8Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MY...
CVE-2026-18401MEDIUM6.9The non-blocking (asynchronous) JSON parser in jackson-core does not enforce the maxNumberLength constraint defined in S...
CVE-2026-11368MEDIUM6.5The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning chann...
CVE-2026-70368MEDIUM6.5A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m...
CVE-2026-70367MEDIUM5.4A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now