2026 CVE Vulnerabilities

65,819 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-97646HIGH7.3A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. T...
CVE-2026-92289CRITICAL9.1Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKC...
CVE-2026-92288CRITICAL9.1Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth...
CVE-2026-85417MEDIUM6.4Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be reco...
CVE-2026-53493MEDIUM6.9containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI...
CVE-2026-85082HIGH8.5Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely sep...
CVE-2026-84283MEDIUM6.8Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-stor...
CVE-2026-97387——Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-97230CRITICAL9.8IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated U...
CVE-2026-97636MEDIUM6.5Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-co...
CVE-2026-87722HIGH8.7Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, ...
CVE-2026-87721HIGH8.7Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerr...
CVE-2026-87720HIGH7.6Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction l...
CVE-2026-85491HIGH8.8Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorizat...
CVE-2026-97368MEDIUM6.3A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInf...
CVE-2026-97366MEDIUM6.3A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function...
CVE-2026-95699CRITICAL9.6Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT ...
CVE-2026-93353MEDIUM5.3copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users ...
CVE-2026-88388HIGH7.5Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace ...
CVE-2026-88387MEDIUM5.5LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF ta...
CVE-2026-88386MEDIUM5.5libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A spec...
CVE-2026-87118MEDIUM5.7The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functiona...
CVE-2026-84403MEDIUM6.2The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access...
CVE-2026-82716MEDIUM4.6The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diag...
CVE-2026-82708MEDIUM6.5The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with acce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now