2026 CVE Vulnerabilities

64,616 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35090CRITICAL9.3In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can conne...
CVE-2026-35089HIGH8.7In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange...
CVE-2026-35087CRITICAL9.3Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter...
CVE-2026-2607MEDIUM5.1IBM MQ Operator SC2: v3.2.0 through 3.2.23CD:  v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 ...
CVE-2026-2340MEDIUM6.5A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections ...
CVE-2026-23679MEDIUM5.5libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applicatio...
CVE-2026-1933MEDIUM6.5A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to miss...
CVE-2026-1718HIGH7.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted q...
CVE-2026-9689MEDIUM4.2A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is confi...
CVE-2026-48906HIGH8.1The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
CVE-2026-45846MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bareudp: fix NULL pointer dereference in bareudp_fi...
CVE-2026-45845MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: fix NULL pointer dereference in ...
CVE-2026-45844MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: arp_tables: fix IEEE1394 ARP payload par...
CVE-2026-45843HIGH8.2In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed p...
CVE-2026-45842MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: slip: reject VJ receive packets on instances with n...
CVE-2026-45841MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_osf: fix divide-by-zero in OSF...
CVE-2026-45840MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: openvswitch: cap upcall PID array size and pre-size...
CVE-2026-45839HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_...
CVE-2026-45838MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: fix end-of-list detection in cgroup_storage_ge...
CVE-2026-45837HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in arena_vm_close on fork ...
CVE-2026-42762HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBookin...
CVE-2026-42761CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active ...
CVE-2026-42760HIGH7.5Authentication Bypass Using an Alternate Path or Channel vulnerability in revmakx Backup and Staging by WP Time Capsule ...
CVE-2026-42759HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Affiliate Sup...
CVE-2026-42758CRITICAL9.8Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privile...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now