2026 CVE Vulnerabilities

50,911 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9628HIGH8.8A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /gofo...
CVE-2026-9627HIGH8.8A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file...
CVE-2026-9207HIGH8.8Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-9156HIGH7.5Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-49017HIGH7.1In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-ch...
CVE-2026-49014HIGH7.8In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buf...
CVE-2026-9606HIGH7.3A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the fil...
CVE-2026-9605HIGH7.3A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c ...
CVE-2026-9312HIGH8.2A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenti...
CVE-2026-9584HIGH7.3A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown functi...
CVE-2026-5260HIGH8.2A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key excha...
CVE-2026-45574HIGH8.1epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on t...
CVE-2026-45298HIGH8.6Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quick...
CVE-2026-44983HIGH7.3smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the inter...
CVE-2026-44905HIGH7.5Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vul...
CVE-2026-44900HIGH8.1epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublic...
CVE-2026-43988HIGH7.5Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vul...
CVE-2026-42013HIGH8.2A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the va...
CVE-2026-42012HIGH7.1A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certifi...
CVE-2026-9580HIGH7.3A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepa...
CVE-2026-8676HIGH8.8An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bo...
CVE-2026-45575HIGH7.4epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who ...
CVE-2026-44847HIGH7.5MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/w...
CVE-2026-44843HIGH8.2LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains...
CVE-2026-44837HIGH7.5view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now