2026 CVE Vulnerabilities

44,807 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-64206HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before tak...
CVE-2026-64191HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid ...
CVE-2026-64189HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_...
CVE-2026-64188HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free i...
CVE-2026-58484HIGH7.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`...
CVE-2026-54538HIGH7.5xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to pr...
CVE-2026-46701HIGH7.6Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e...
CVE-2026-46555HIGH7.7WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes...
CVE-2026-44178HIGH8.8xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within t...
CVE-2026-40187HIGH8.6In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) ...
CVE-2026-39879HIGH7.1Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb...
CVE-2026-39385HIGH7.1Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment vali...
CVE-2026-35591HIGH7libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an...
CVE-2026-33327HIGH7libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ...
CVE-2026-32825HIGH7.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32824HIGH7.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32821HIGH8.1dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32820HIGH7.5dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32806HIGH7.5dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-63429HIGH8.6HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no ...
CVE-2026-46415HIGH8.2The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the clien...
CVE-2026-45713HIGH7.5Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.M...
CVE-2026-45711HIGH8.2Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http <base-url> <ou...
CVE-2026-32807HIGH7.5dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-27823HIGH8.7A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an auth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now