2026 CVE Vulnerabilities

59,302 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6687HIGH7.6FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trus...
CVE-2026-6686MEDIUM4.6FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-...
CVE-2026-6685Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority following a notification that...
CVE-2026-6684MEDIUM4.6FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived f...
CVE-2026-6683MEDIUM4.6FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to b...
CVE-2026-6682HIGH7.6In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, ...
CVE-2026-6283MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa...
CVE-2026-5220MEDIUM6.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa...
CVE-2026-5142MEDIUM6.5A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing t...
CVE-2026-5138MEDIUM4.3A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information d...
CVE-2026-5135MEDIUM6.5A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permis...
CVE-2026-58399HIGH8.7@acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unaut...
CVE-2026-58035MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58034MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58031MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-2891HIGH8.2The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP serve...
CVE-2026-23537CRITICAL9.1A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticat...
CVE-2026-14330MEDIUM5.5Multiple unbounded alloca() calls in the PulseAudio protocol server.
CVE-2026-14324MEDIUM6.5RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVE-2026-13602HIGH7.7We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the ...
CVE-2026-12374MEDIUM6.4Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC ...
CVE-2026-5136HIGH8.8A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call...
CVE-2026-57692CRITICAL9.8Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects Pr...
CVE-2026-53356HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset ...
CVE-2026-53355CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now