2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-70619HIGH8.8Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users ...
CVE-2026-67862HIGH7.5open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c...
CVE-2026-67861HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemo...
CVE-2026-67860HIGH7.5open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database ...
CVE-2026-67859HIGH7.5Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discover...
CVE-2026-67858HIGH7.5Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast di...
CVE-2026-67857HIGH7.5open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/u...
CVE-2026-67856HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscri...
CVE-2026-67855HIGH7.5open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMA...
CVE-2026-45103HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP...
CVE-2026-45084HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of ...
CVE-2026-18814HIGH7.3A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. Th...
CVE-2026-70494HIGH8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE...
CVE-2026-70492HIGH8.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/...
CVE-2026-66901HIGH7.5Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated...
CVE-2026-65986HIGH8.5CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 co...
CVE-2026-51401HIGH7.7An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(...
CVE-2026-51400HIGH8.4An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(...
CVE-2026-18813HIGH7.3A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipul...
CVE-2026-18812HIGH7.3A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Ex...
CVE-2026-18811HIGH7.3A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Perfo...
CVE-2026-13227HIGH7.1An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access co...
CVE-2026-70486HIGH8.2Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the termi...
CVE-2026-70485HIGH7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebU...
CVE-2026-70482HIGH8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now