2026 CVE Vulnerabilities

64,377 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35675HIGH8.8phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthe...
CVE-2026-35672HIGH8.7phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientT...
CVE-2026-35671HIGH8.8phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint...
CVE-2026-9828LOW2.9Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-...
CVE-2026-8990MEDIUM5.3A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant...
CVE-2026-8980CRITICAL9.3The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-priv...
CVE-2026-8979CRITICAL9.3The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated re...
CVE-2026-49238HIGH8.4An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server)...
CVE-2026-49237HIGH7.8An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-519...
CVE-2026-42250MEDIUM4.8bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the applicatio...
CVE-2026-37579HIGH7.3An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMe...
CVE-2026-37266HIGH8An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary ...
CVE-2026-9818——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9658HIGH7.3Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. T...
CVE-2026-40914MEDIUM4.3A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that ...
CVE-2026-9813CRITICAL9.9FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL ...
CVE-2026-4377MEDIUM6Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it...
CVE-2026-47074HIGH8.7Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows ...
CVE-2026-46241HIGH7.8In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on registration fa...
CVE-2026-46240HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix use-after-free in iris_release_int...
CVE-2026-46239MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Fix runtime PM refcount leak in...
CVE-2026-46238HIGH8.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned originator pointer...
CVE-2026-46237——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-46236MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: rc: xbox_remote: heed DMA restrictions The ...
CVE-2026-46235MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: saa7164: add ioremap return checks and clean...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now