2026 CVE Vulnerabilities
59,302 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6687 | HIGH | 7.6 | 0.2% | Jul 1, 2026 | FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trus... |
| CVE-2026-6686 | MEDIUM | 4.6 | 0.2% | Jul 1, 2026 | FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-... |
| CVE-2026-6685 | — | — | 0.2% | Jul 1, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority following a notification that... |
| CVE-2026-6684 | MEDIUM | 4.6 | 0.2% | Jul 1, 2026 | FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived f... |
| CVE-2026-6683 | MEDIUM | 4.6 | 0.2% | Jul 1, 2026 | FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to b... |
| CVE-2026-6682 | HIGH | 7.6 | 0.2% | Jul 1, 2026 | In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, ... |
| CVE-2026-6283 | MEDIUM | 5.4 | — | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa... |
| CVE-2026-5220 | MEDIUM | 6.4 | — | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa... |
| CVE-2026-5142 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing t... |
| CVE-2026-5138 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information d... |
| CVE-2026-5135 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permis... |
| CVE-2026-58399 | HIGH | 8.7 | 0.5% | Jul 1, 2026 | @acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unaut... |
| CVE-2026-58035 | MEDIUM | 4.8 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58034 | MEDIUM | 4.8 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58031 | MEDIUM | 5.4 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-2891 | HIGH | 8.2 | 0.3% | Jul 1, 2026 | The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP serve... |
| CVE-2026-23537 | CRITICAL | 9.1 | 0.6% | Jul 1, 2026 | A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticat... |
| CVE-2026-14330 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | Multiple unbounded alloca() calls in the PulseAudio protocol server. |
| CVE-2026-14324 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. |
| CVE-2026-13602 | HIGH | 7.7 | 0.2% | Jul 1, 2026 | We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the ... |
| CVE-2026-12374 | MEDIUM | 6.4 | 0.1% | Jul 1, 2026 | Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC ... |
| CVE-2026-5136 | HIGH | 8.8 | 0.3% | Jul 1, 2026 | A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call... |
| CVE-2026-57692 | CRITICAL | 9.8 | — | Jul 1, 2026 | Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects Pr... |
| CVE-2026-53356 | HIGH | 7.8 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset ... |
| CVE-2026-53355 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now