2026 CVE Vulnerabilities

61,683 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50232HIGH7.2Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious...
CVE-2026-50231HIGH7.2Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that a...
CVE-2026-50230MEDIUM6.1Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log end...
CVE-2026-38500Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2026-11369HIGH7.1The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization chec...
CVE-2026-11330LOW3.6A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObserv...
CVE-2026-11329LOW3.6A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key...
CVE-2026-50264HIGH7.8An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A cli...
CVE-2026-50263MEDIUM5.5A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-af...
CVE-2026-50262MEDIUM5.5An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong...
CVE-2026-50261HIGH7.8A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multipl...
CVE-2026-50260HIGH7.8A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple Sync...
CVE-2026-50259HIGH7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-siz...
CVE-2026-50258HIGH7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers...
CVE-2026-50257HIGH7.8A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multip...
CVE-2026-50256HIGH7.8A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the...
CVE-2026-25659MEDIUM6.5Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulne...
CVE-2026-25658MEDIUM6.5Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulne...
CVE-2026-25657MEDIUM6.5Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structur...
CVE-2026-11346MEDIUM5.3A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticat...
CVE-2026-11345MEDIUM6.9An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attack...
CVE-2026-8914HIGH8.4In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 throug...
CVE-2026-50265Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
CVE-2026-21038MEDIUM5.5Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to ac...
CVE-2026-21037HIGH7.1Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now