2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-86443MEDIUM6.9Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an ...
CVE-2026-84501MEDIUM5.3An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a cra...
CVE-2026-84439MEDIUM5.3When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields int...
CVE-2026-77190MEDIUM6.5On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to ...
CVE-2026-76151MEDIUM4.6Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Gr...
CVE-2026-73469MEDIUM5.8When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain ...
CVE-2026-73468MEDIUM6.5A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentia...
CVE-2026-73440MEDIUM4.2On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remo...
CVE-2026-73438MEDIUM5.3On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated...
CVE-2026-73436MEDIUM6.5On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 p...
CVE-2026-19640MEDIUM4.2On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interfa...
CVE-2026-92081MEDIUM5.9fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a respon...
CVE-2026-89186MEDIUM6.3Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and ser...
CVE-2026-88255MEDIUM6.3Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Te...
CVE-2026-86465MEDIUM6.5Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled...
CVE-2026-86338MEDIUM6Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not...
CVE-2026-82720MEDIUM5.9NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs...
CVE-2026-78227MEDIUM6.5NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC...
CVE-2026-77955MEDIUM4.4In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) ...
CVE-2026-73463MEDIUM5.3On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured...
CVE-2026-73445MEDIUM4.9On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may ...
CVE-2026-92091MEDIUM5.9A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using ...
CVE-2026-89207MEDIUM6.5A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (...
CVE-2026-86341MEDIUM4.4GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3...
CVE-2026-81326MEDIUM6.8QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the aff...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now