2026 CVE Vulnerabilities

53,410 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24819MEDIUM6.3Improperly Controlled Sequential Memory Allocation vulnerability in foxinmy weixin4j (weixin4j-base/src/main/java/com/fo...
CVE-2026-24818MEDIUM6.9Out-of-bounds Read vulnerability in praydog UEVR (dependencies/lua/src modules). This vulnerability is associated with p...
CVE-2026-24809MEDIUM6.9An issue from the component luaG_runerror in dependencies/lua/src/ldebug.c in praydog/REFramework version before 1.5.5 l...
CVE-2026-24807MEDIUM5.3Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-f...
CVE-2026-24806MEDIUM5.3Improper Control of Generation of Code ('Code Injection') vulnerability in liuyueyi quick-media (plugins/svg-plugin/bati...
CVE-2026-24805MEDIUM6.7NULL Pointer Dereference vulnerability in visualfc liteide (liteidex/src/3rdparty/libvterm/src modules). This vulnerabil...
CVE-2026-24802MEDIUM5.3Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in briandilley jsonrpc4j (src/main/java/com/googlec...
CVE-2026-24801MEDIUM6.9Vulnerability in Ralim IronOS (source/Core/BSP/Pinecilv2/bl_mcu_sdk/components/ble/ble_stack/common/tinycrypt/source mod...
CVE-2026-24799MEDIUM5.2Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in davisking d...
CVE-2026-24797MEDIUM6.9Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerabili...
CVE-2026-24796MEDIUM6.9Out-of-bounds Read vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Onigu...
CVE-2026-24795MEDIUM5.1Out-of-bounds Write vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Onig...
CVE-2026-1464MEDIUM4.6Integer Overflow or Wraparound vulnerability in MuntashirAkon AppManager (app/src/main/java/org/apache/commons/compress/...
CVE-2026-24686MEDIUM4.7go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repositor...
CVE-2026-24490MEDIUM4.8MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vu...
CVE-2026-24489MEDIUM5.3Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in ...
CVE-2026-23683MEDIUM4.3SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated u...
CVE-2026-24476MEDIUM5.4Shaarli is a personal bookmarking service. Prior to version 0.16.0, crafting a malicious tag which starting with `"` pre...
CVE-2026-24408MEDIUM5sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-...
CVE-2026-24123MEDIUM6.5BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to vers...
CVE-2026-24131MEDIUM5.5pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `p...
CVE-2026-24056MEDIUM6.5pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it f...
CVE-2026-24003MEDIUM5.3EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequen...
CVE-2026-23890MEDIUM6.5pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicio...
CVE-2026-23889MEDIUM6.5pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now