2026 CVE Vulnerabilities

66,522 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93208——In the Linux kernel, the following vulnerability has been resolved: kasan: fix cache shrink race with CPU hotplug kasa...
CVE-2026-93207CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decod...
CVE-2026-93206——In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking confi...
CVE-2026-93205——In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Manage teardown with devm arm_s...
CVE-2026-92680MEDIUM5.5Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the W...
CVE-2026-88371——ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing sp...
CVE-2026-88370MEDIUM5.3libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and stri...
CVE-2026-88369HIGH7.3zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().
CVE-2026-88368HIGH7.5NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() fu...
CVE-2026-88366——NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG ar...
CVE-2026-88365CRITICAL9.8minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-siz...
CVE-2026-88362HIGH7.5MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted J...
CVE-2026-88361HIGH7.5SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLab...
CVE-2026-88358MEDIUM6.5simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafte...
CVE-2026-88357HIGH7.5nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted ne...
CVE-2026-88355——An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expressi...
CVE-2026-79761MEDIUM6.6Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-79760MEDIUM6.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0...
CVE-2026-79759MEDIUM4.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-79758MEDIUM5.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0...
CVE-2026-77581HIGH8.6BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS pr...
CVE-2026-76907MEDIUM6.5LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/docum...
CVE-2026-75907HIGH7.5The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID s...
CVE-2026-67233MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel ma...
CVE-2026-63630LOW3.4BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Tim...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now