2026 CVE Vulnerabilities

65,828 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-95699CRITICAL9.6Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT ...
CVE-2026-93353MEDIUM5.3copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users ...
CVE-2026-88388HIGH7.5Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace ...
CVE-2026-88387MEDIUM5.5LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF ta...
CVE-2026-88386MEDIUM5.5libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A spec...
CVE-2026-87118MEDIUM5.7The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functiona...
CVE-2026-84403MEDIUM6.2The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access...
CVE-2026-82716MEDIUM4.6The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diag...
CVE-2026-82708MEDIUM6.5The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with acce...
CVE-2026-82585MEDIUM6.5The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An at...
CVE-2026-81630HIGH8.1The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update proce...
CVE-2026-79959MEDIUM6.8The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. A...
CVE-2026-75558MEDIUM5.3The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi cre...
CVE-2026-14443HIGH8.4Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extensio...
CVE-2026-14442MEDIUM6.9An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be writt...
CVE-2026-14441MEDIUM6.9A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when pro...
CVE-2026-97365MEDIUM6.3A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file cr...
CVE-2026-97326HIGH7.3A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this i...
CVE-2026-97325MEDIUM4.3A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability ...
CVE-2026-97324HIGH7.3A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoO...
CVE-2026-96883HIGH8.8pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 m...
CVE-2026-93354HIGH8.1Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers t...
CVE-2026-93291CRITICAL9.4Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which c...
CVE-2026-93290MEDIUM5.5Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access i...
CVE-2026-93289HIGH7.5The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now