2026 CVE Vulnerabilities

49,055 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-38570HIGH7.5bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial o...
CVE-2026-10814HIGH7A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file int...
CVE-2026-41065HIGH8.9Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable t...
CVE-2026-36176HIGH7.1GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial c...
CVE-2026-28318HIGH7.5SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication...
CVE-2026-10863HIGH8.1A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted fr...
CVE-2026-45433HIGH8.7This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device...
CVE-2026-45432HIGH8.7This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in i...
CVE-2026-45431HIGH8.7This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic ...
CVE-2026-10843HIGH7.2A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are pro...
CVE-2026-10840HIGH7.1A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys...
CVE-2026-49771HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Galler...
CVE-2026-50213HIGH7.5The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled b...
CVE-2026-50210HIGH7.5The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to re...
CVE-2026-50209HIGH7.8Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres...
CVE-2026-50207HIGH7.8The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read base...
CVE-2026-3820HIGH7.2There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain admini...
CVE-2026-50205HIGH8.2System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identifi...
CVE-2026-49203HIGH8.3Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof...
CVE-2026-49202HIGH8.6Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S...
CVE-2026-49194HIGH8.8The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire...
CVE-2026-49193HIGH7.5Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the...
CVE-2026-49190HIGH8.8The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unau...
CVE-2026-49189HIGH7.8Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke ...
CVE-2026-49187HIGH7.5The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now