2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-67185HIGH8.7TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary fi...
CVE-2026-67184HIGH8.7TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to ...
CVE-2026-67183HIGH8.7TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available me...
CVE-2026-67182HIGH7.5Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass acce...
CVE-2026-54620LOW2sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite agg...
CVE-2026-54619LOW2sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite func...
CVE-2026-54609HIGH8.6QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handle...
CVE-2026-54605HIGH7.2OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth:...
CVE-2026-54603HIGH8.6OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0...
CVE-2026-54345HIGH7.5gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes...
CVE-2026-54332HIGH7.5gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow dec...
CVE-2026-51275Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51274Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51273Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-18085MEDIUM6.9An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows A...
CVE-2026-18084MEDIUM6.1Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackB...
CVE-2026-16313HIGH7.6A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification ...
CVE-2026-8058MEDIUM4.5IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resou...
CVE-2026-7868MEDIUM6.5IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges an...
CVE-2026-7775MEDIUM4.8IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM St...
CVE-2026-67181MEDIUM5.4Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchroni...
CVE-2026-66754HIGH8.2Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that all...
CVE-2026-66753MEDIUM6.3tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return...
CVE-2026-66752MEDIUM6.3tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize ...
CVE-2026-66751MEDIUM5.4Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to ar...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now