2026 CVE Vulnerabilities

50,954 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70368MEDIUM6.5A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m...
CVE-2026-70367MEDIUM5.4A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr...
CVE-2026-17070HIGH8.8Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b...
CVE-2026-14337MEDIUM4.6Pega Platform versions 23.1.0 through 25.1.3 are affected by an Stored Cross-site scripting (XSS) vulnerability in a use...
CVE-2026-70373HIGH8.8Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by conc...
CVE-2026-70372HIGH8.8Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request pa...
CVE-2026-70371HIGH8.8Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request ...
CVE-2026-70370HIGH8.8Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Colu...
CVE-2026-70369HIGH8.8Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-con...
CVE-2026-63252HIGH7.5In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message ch...
CVE-2026-63248MEDIUM6.5In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an...
CVE-2026-62927HIGH7.5In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space hand...
CVE-2026-61387HIGH7.5In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa...
CVE-2026-60007HIGH7.4In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA P...
CVE-2026-58080HIGH8.2In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On...
CVE-2026-18809MEDIUM6.5Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153...
CVE-2026-18806HIGH7.1External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-im...
CVE-2026-10710HIGH7.8A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab...
CVE-2026-10709HIGH7.8A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerab...
CVE-2026-66884LOW2.1Cross-Site Request Forgery vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.AuthorizationCallback mod...
CVE-2026-66883MEDIUM6.3Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize modu...
CVE-2026-10050CRITICAL9.1In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. Th...
CVE-2026-18772MEDIUM6.5Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data ...
CVE-2026-15721CRITICAL9.8Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Dig...
CVE-2026-14838HIGH7.4Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now