2026 CVE Vulnerabilities

61,555 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6899MEDIUM5.6Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in th...
CVE-2026-49818MEDIUM6.5The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c...
CVE-2026-46315MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying i...
CVE-2026-34905MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An...
CVE-2026-34033MEDIUM5.4Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer. This issu...
CVE-2026-34031MEDIUM6.5Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu...
CVE-2026-33582MEDIUM6.5Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: throu...
CVE-2026-28262MEDIUM6Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following')...
CVE-2026-25699MEDIUM6.1Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Ap...
CVE-2026-25688MEDIUM6.1Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: throu...
CVE-2026-11616HIGH8.8The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and in...
CVE-2026-9698CRITICAL9.8DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when Raise...
CVE-2026-5068HIGH8.8A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD...
CVE-2026-44083CRITICAL9.8An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attack...
CVE-2026-41986LOW2.4Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi...
CVE-2026-41985MEDIUM5.1UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser...
CVE-2026-41984MEDIUM5.2UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect ser...
CVE-2026-41983MEDIUM4.3Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may ...
CVE-2026-41982MEDIUM6.4Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availab...
CVE-2026-41981MEDIUM5.3Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect av...
CVE-2026-41977MEDIUM5DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-41976MEDIUM6.6Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affec...
CVE-2026-41974LOW3.6Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff...
CVE-2026-41973MEDIUM5.9Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability...
CVE-2026-41972MEDIUM5.4Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availabili...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now