2026 CVE Vulnerabilities

60,155 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52955CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crus...
CVE-2026-52954HIGH7.5In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_ch...
CVE-2026-52953HIGH7.1In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix oops due to out of scope access Be...
CVE-2026-52952HIGH8.8In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofa...
CVE-2026-52951HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: handle empty bo and UAF races Ther...
CVE-2026-52950HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry does...
CVE-2026-52949MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on b...
CVE-2026-52948MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT i...
CVE-2026-52947HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UA...
CVE-2026-52946HIGH7.5In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync s...
CVE-2026-52945HIGH7.5In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" T...
CVE-2026-13164HIGH8.8Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /ap...
CVE-2026-56121CRITICAL9.8Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attacke...
CVE-2026-56119Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56118Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56111CRITICAL9.1Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-...
CVE-2026-55488HIGH7.7motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w...
CVE-2026-50712MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50711MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50710MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation...
CVE-2026-50709MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50708MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50705MEDIUM4.6A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization ...
CVE-2026-50704MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50703MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now