2026 CVE Vulnerabilities
60,155 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52955 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in crus... |
| CVE-2026-52954 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: handle rbtree insertion error in decode_ch... |
| CVE-2026-52953 | HIGH | 7.1 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix oops due to out of scope access Be... |
| CVE-2026-52952 | HIGH | 8.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofa... |
| CVE-2026-52951 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: handle empty bo and UAF races Ther... |
| CVE-2026-52950 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry does... |
| CVE-2026-52949 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on b... |
| CVE-2026-52948 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: dev: prevent integer overflow in I2C_TIMEOUT i... |
| CVE-2026-52947 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UA... |
| CVE-2026-52946 | HIGH | 7.5 | 0.6% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync s... |
| CVE-2026-52945 | HIGH | 7.5 | 0.3% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" T... |
| CVE-2026-13164 | HIGH | 8.8 | 0.4% | Jun 24, 2026 | Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /ap... |
| CVE-2026-56121 | CRITICAL | 9.8 | 1.4% | Jun 24, 2026 | Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attacke... |
| CVE-2026-56119 | — | — | — | Jun 24, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-56118 | — | — | — | Jun 24, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-56111 | CRITICAL | 9.1 | 0.5% | Jun 24, 2026 | Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-... |
| CVE-2026-55488 | HIGH | 7.7 | 0.6% | Jun 24, 2026 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w... |
| CVE-2026-50712 | MEDIUM | 4.8 | 0.2% | Jun 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali... |
| CVE-2026-50711 | MEDIUM | 4.6 | 0.3% | Jun 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali... |
| CVE-2026-50710 | MEDIUM | 4.6 | 0.3% | Jun 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation... |
| CVE-2026-50709 | MEDIUM | 4.8 | 0.2% | Jun 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali... |
| CVE-2026-50708 | MEDIUM | 4.8 | 0.2% | Jun 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali... |
| CVE-2026-50705 | MEDIUM | 4.6 | 0.3% | Jun 24, 2026 | A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization ... |
| CVE-2026-50704 | MEDIUM | 4.6 | 0.3% | Jun 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali... |
| CVE-2026-50703 | MEDIUM | 4.8 | 0.2% | Jun 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now