2026 CVE Vulnerabilities

64,604 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8175CRITICAL9.8IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 t...
CVE-2026-7876CRITICAL9.1IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client m...
CVE-2026-7528HIGH7.5IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
CVE-2026-7524CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links duri...
CVE-2026-7365HIGH7.8IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default pass...
CVE-2026-7254MEDIUM5.3IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
CVE-2026-6938HIGH7.5IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with ...
CVE-2026-6936MEDIUM6.5IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated ...
CVE-2026-6053MEDIUM5.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted q...
CVE-2026-6052HIGH7.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain q...
CVE-2026-6051HIGH7.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially...
CVE-2026-5516MEDIUM5.9IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could all...
CVE-2026-5515MEDIUM5.5IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be...
CVE-2026-5065HIGH8.8IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic k...
CVE-2026-4410HIGH7.5IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 a...
CVE-2026-48972HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-48971MEDIUM4.3Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Con...
CVE-2026-47104MEDIUM5.5libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c t...
CVE-2026-46103MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: can: ucan: fix devres lifetime USB drivers bind to...
CVE-2026-46102HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net: strparser: fix skb_head leak in strp_abort_str...
CVE-2026-46101MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: reject zero shift in nft_bitwise Reject...
CVE-2026-46100HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs: afs: revert mmap_prepare() change Partially re...
CVE-2026-46099HIGH8.1In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunn...
CVE-2026-46098MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: caif: clear client service pointer on teardown...
CVE-2026-46097HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Input: edt-ft5x06 - fix use-after-free in debugfs t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now