2026 CVE Vulnerabilities

59,993 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53283MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bounds-check devid in __rlookup_amd_iomm...
CVE-2026-53282MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/kexec: Push kjump return address even for non-k...
CVE-2026-53281HIGH8.8In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refco...
CVE-2026-53280MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: iommu: Fix NULL group->domain dereference in pci_de...
CVE-2026-53279MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/gma500/oaktrail_lvds: fix hang on init failure ...
CVE-2026-53278MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Check whether the config array is allocat...
CVE-2026-52785CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection ...
CVE-2026-52784HIGH8.8OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET...
CVE-2026-52783HIGH8.2OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages mo...
CVE-2026-52782CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through ...
CVE-2026-52781MEDIUM6.4OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants...
CVE-2026-52780CRITICAL9.6OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning lea...
CVE-2026-52779MEDIUM5.4OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / au...
CVE-2026-49991HIGH8.6RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject pe...
CVE-2026-49355MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.4.0, `GET /api/v3/meetings/:meeting_id/ag...
CVE-2026-47193HIGH7.5OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint...
CVE-2026-46386CRITICAL9.9OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke...
CVE-2026-44736MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint a...
CVE-2026-44735MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares en...
CVE-2026-44734MEDIUM6.5OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization v...
CVE-2026-44733MEDIUM5.9OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on O...
CVE-2026-44732MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, OpenProject exposes a doc...
CVE-2026-44731MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the web application's mee...
CVE-2026-44696MEDIUM5.7OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) r...
CVE-2026-32833HIGH8.8Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now