2026 CVE Vulnerabilities

61,548 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25089CRITICAL9.8A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F...
CVE-2026-24065HIGH8.1Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privile...
CVE-2026-24064HIGH7.8Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC...
CVE-2026-10727HIGH7.2An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote aut...
CVE-2026-10523CRITICAL9.8An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow...
CVE-2026-10520CRITICAL10An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote ...
CVE-2026-9279HIGH8.7Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts t...
CVE-2026-7486CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software In...
CVE-2026-52907HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change...
CVE-2026-52906HIGH7.7In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep...
CVE-2026-52905MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region...
CVE-2026-52904MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device leak on aperture remov...
CVE-2026-49762MEDIUM5.1Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who c...
CVE-2026-47901MEDIUM4.6Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attri...
CVE-2026-47900MEDIUM4.6Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the ...
CVE-2026-47899HIGH8.7The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers with...
CVE-2026-46332HIGH8In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu...
CVE-2026-46330HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This r...
CVE-2026-46329MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-b...
CVE-2026-46328HIGH7.3In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cp...
CVE-2026-46327HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The func...
CVE-2026-46326HIGH8.4In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct...
CVE-2026-46325CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page siz...
CVE-2026-11793MEDIUM4.9A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co...
CVE-2026-11792LOW3.3A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_st...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now