2026 CVE Vulnerabilities

60,172 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52947HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UA...
CVE-2026-52946HIGH7.5In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync s...
CVE-2026-52945HIGH7.5In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" T...
CVE-2026-13164HIGH8.8Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /ap...
CVE-2026-56121CRITICAL9.8Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attacke...
CVE-2026-56119Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56118Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56111CRITICAL9.1Marlin Firmware through 2.1.2.7, fixed in commit 1f255d1, when built with MESH_BED_LEVELING enabled, contains an out-of-...
CVE-2026-55488HIGH7.7motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w...
CVE-2026-50712MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50711MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50710MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation...
CVE-2026-50709MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50708MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50705MEDIUM4.6A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization ...
CVE-2026-50704MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50703MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-50701MEDIUM5.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutr...
CVE-2026-50700MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-49269HIGH8.6Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal at...
CVE-2026-50699MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attack...
CVE-2026-50698MEDIUM4.6A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutrali...
CVE-2026-12986HIGH7.3A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All plat...
CVE-2026-11878MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Ma...
CVE-2026-11877HIGH7.5An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue aff...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now