2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5980HIGH8.8A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /g...
CVE-2026-5979HIGH8.8A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ ...
CVE-2026-5447HIGH7.5Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when conve...
CVE-2026-5446HIGH7.1In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every applicati...
CVE-2026-40093HIGH8.1nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestam...
CVE-2026-4436HIGH8.6A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant i...
CVE-2026-35577HIGH8.1Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7....
CVE-2026-35063HIGH8.8OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with r...
CVE-2026-34734HIGH7.8HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utilit...
CVE-2026-34487HIGH7.5Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apach...
CVE-2026-34486HIGH7.5Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypas...
CVE-2026-34483HIGH7.5Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue ...
CVE-2026-29923HIGH7.8The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a...
CVE-2026-29146HIGH7.5Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apach...
CVE-2026-29129HIGH7.5Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from...
CVE-2026-24880HIGH7.5Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via inva...
CVE-2026-35556HIGH7.5OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve cre...
CVE-2026-35186HIGH7.5Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backe...
CVE-2026-34946HIGH7.5Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta...
CVE-2026-34943HIGH7.5Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic w...
CVE-2026-34941HIGH8.1Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability wh...
CVE-2026-40072HIGH7.2web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web...
CVE-2026-40070HIGH8.1BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certi...
CVE-2026-40069HIGH7.5BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection o...
CVE-2026-39983HIGH8.6basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n)...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now