2026 CVE Vulnerabilities

65,269 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-98164——In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address s...
CVE-2026-96869——Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and ...
CVE-2026-82973CRITICAL9.4Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a r...
CVE-2026-82804——The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharac...
CVE-2026-7193HIGH8.6A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attack...
CVE-2026-7192CRITICAL9.3A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to...
CVE-2026-76875MEDIUM5.3PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityP...
CVE-2026-76114MEDIUM5.9Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sen...
CVE-2026-73599MEDIUM5.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted...
CVE-2026-73598HIGH7.8Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignm...
CVE-2026-102437HIGH7.8OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasoni...
CVE-2026-101271LOW2.1OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) t...
CVE-2026-101270LOW2.1Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
CVE-2026-101269LOW2.3The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same s...
CVE-2026-101268LOW1.7If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's custo...
CVE-2026-101267LOW2.7A missing permission check allowed low-privileged users with access to an event but without access to the event's orders...
CVE-2026-100832HIGH8.8Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox ESR 115.4...
CVE-2026-100831HIGH8.8Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and F...
CVE-2026-100830——Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100829——Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100828——Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 15...
CVE-2026-100826——Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefo...
CVE-2026-100825HIGH8.8Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 15...
CVE-2026-100824——Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
CVE-2026-100823——Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now