2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-45545HIGH8.2Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10,...
CVE-2026-45302HIGH8.2parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0....
CVE-2026-45284HIGH8.8Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper chec...
CVE-2026-45281HIGH8.1Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-43958HIGH7.8A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a ...
CVE-2026-43625HIGH8.2CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo...
CVE-2026-43624HIGH8.8F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauth...
CVE-2026-43623HIGH8.8microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/micro...
CVE-2026-41013HIGH8.1Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF s...
CVE-2026-37235HIGH7.5FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. T...
CVE-2026-37233HIGH7.5FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ri...
CVE-2026-37232HIGH8.6An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric...
CVE-2026-37231HIGH7.5FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,...
CVE-2026-37230HIGH7.5FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in ...
CVE-2026-37229HIGH7.5FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote una...
CVE-2026-37228HIGH7.5FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a f...
CVE-2026-37226HIGH7.5FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lo...
CVE-2026-10281HIGH7.3A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of th...
CVE-2026-10280HIGH7.3A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file...
CVE-2026-0072HIGH7.8In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission che...
CVE-2026-8501HIGH7.8Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode proc...
CVE-2026-46243HIGH7.1In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descripti...
CVE-2026-45156HIGH8.1Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, ...
CVE-2026-42678HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / Stell...
CVE-2026-42677HIGH7.5Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now