2026 CVE Vulnerabilities

61,548 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11790MEDIUM4.9A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t...
CVE-2026-11789MEDIUM6.5A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp...
CVE-2026-11788HIGH7.5A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us...
CVE-2026-11787MEDIUM6.3A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without ...
CVE-2026-11786MEDIUM6.5A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute ...
CVE-2026-11785MEDIUM4.3A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial st...
CVE-2026-46324HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink ...
CVE-2026-46323HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive()...
CVE-2026-46322HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one(...
CVE-2026-46321HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_...
CVE-2026-46320HIGH7.4In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp()...
CVE-2026-46319HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after...
CVE-2026-46318MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_...
CVE-2026-46317HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_l...
CVE-2026-46316CRITICAL9.3In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re...
CVE-2026-2638HIGH7.3A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a loc...
CVE-2026-11764LOW3.6When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if ...
CVE-2026-49742HIGH7.1Backend users with file download permissions were able to download files from the fallback storage of the file abstracti...
CVE-2026-49741HIGH8.7Backend users with write access to the form_definition database table were able to directly create, update, or delete fo...
CVE-2026-49740MEDIUM6.3TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in...
CVE-2026-49738LOW2.1The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir...
CVE-2026-47352MEDIUM5.3Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission...
CVE-2026-47351MEDIUM5.3Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch...
CVE-2026-47350MEDIUM5.3Backend users were able to move records to a different page without having edit permissions on the source page. This iss...
CVE-2026-47349MEDIUM5.3Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now