2026 CVE Vulnerabilities

43,862 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-68094In the Linux kernel, the following vulnerability has been resolved: sched_ext: Preserve rq tracking across local DSQ di...
CVE-2026-68093In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Bump asid_generation on CPU online to avo...
CVE-2026-59233HIGH8.7Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authent...
CVE-2026-59090HIGH8.4A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` ...
CVE-2026-19429Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-19278MEDIUM6.8A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configu...
CVE-2026-18370MEDIUM4.8entr is vulnerable to Heap-based buffer overflow in run_utility() function. The function allocates a fixed-size heap buf...
CVE-2026-13206CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networ...
CVE-2026-12984HIGH8.2Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. T...
CVE-2026-68092In the Linux kernel, the following vulnerability has been resolved: time/jiffies: Register jiffies clocksource before u...
CVE-2026-68091HIGH8.8In the Linux kernel, the following vulnerability has been resolved: HID: wacom: stop hardware after post-start probe fa...
CVE-2026-68090In the Linux kernel, the following vulnerability has been resolved: debugobjects: Plug race against a concurrent OOM di...
CVE-2026-68089In the Linux kernel, the following vulnerability has been resolved: iio: core: fix uninitialized data in debugfs If *p...
CVE-2026-68088In the Linux kernel, the following vulnerability has been resolved: usb: gadget: function: rndis: add length check to r...
CVE-2026-68087In the Linux kernel, the following vulnerability has been resolved: HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush...
CVE-2026-68086In the Linux kernel, the following vulnerability has been resolved: mm/khugepaged: write all dirty file folios when col...
CVE-2026-68085HIGH8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: clear HCI_UART_SENDING when wr...
CVE-2026-68084In the Linux kernel, the following vulnerability has been resolved: staging: vme_user: fix location monitor leak in tsi...
CVE-2026-68083CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_c...
CVE-2026-64941LOW2.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attack...
CVE-2026-59088MEDIUM5.5A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI im...
CVE-2026-72594HIGH7.6A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic...
CVE-2026-72593CRITICAL9.8A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to acce...
CVE-2026-72592CRITICAL9.8An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to e...
CVE-2026-72591HIGH7.7A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now