2026 CVE Vulnerabilities

67,120 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93206——In the Linux kernel, the following vulnerability has been resolved: PCI/proc: Use file_ns_capable() when checking confi...
CVE-2026-93205——In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3: Manage teardown with devm arm_s...
CVE-2026-92680MEDIUM5.5Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the W...
CVE-2026-88371——ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing sp...
CVE-2026-88370MEDIUM5.3libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and stri...
CVE-2026-88369HIGH7.3zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().
CVE-2026-88368HIGH7.5NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() fu...
CVE-2026-88366——NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG ar...
CVE-2026-88365CRITICAL9.8minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-siz...
CVE-2026-88362HIGH7.5MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted J...
CVE-2026-88361HIGH7.5SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLab...
CVE-2026-88358MEDIUM6.5simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafte...
CVE-2026-88357HIGH7.5nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted ne...
CVE-2026-88355——An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expressi...
CVE-2026-79761MEDIUM6.6Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-79760MEDIUM6.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0...
CVE-2026-79759MEDIUM4.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-79758MEDIUM5.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0...
CVE-2026-77581HIGH8.6BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS pr...
CVE-2026-76907MEDIUM6.5LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/docum...
CVE-2026-75907HIGH7.5The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID s...
CVE-2026-67233MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel ma...
CVE-2026-63630LOW3.4BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Tim...
CVE-2026-63203HIGH7.6Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API han...
CVE-2026-56739HIGH8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now