2026 CVE Vulnerabilities

64,678 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-36189MEDIUM6.2Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e...
CVE-2026-1816MEDIUM6.3Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation ...
CVE-2026-1815MEDIUM5.7Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application...
CVE-2026-45208HIGH7.8A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges ...
CVE-2026-45207HIGH7.8An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe...
CVE-2026-45206HIGH7.8An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe...
CVE-2026-34930HIGH7.8An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe...
CVE-2026-34929HIGH7.8An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe...
CVE-2026-34928HIGH7.8An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe...
CVE-2026-34927HIGH7.8An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affe...
CVE-2026-34926MEDIUM6.7A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker t...
CVE-2026-2740HIGH8.4Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus bef...
CVE-2026-6841MEDIUM6.1Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET re...
CVE-2026-5118CRITICAL9.8The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2...
CVE-2026-45760HIGH8.1(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vu...
CVE-2026-43502HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/rds: handle zerocopy send cleanup before the me...
CVE-2026-43501CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompress...
CVE-2026-43499HIGH7.8In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in rem...
CVE-2026-43498HIGH7.8In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Disallow re-exporting imported GEM obje...
CVE-2026-43497HIGH7.3In the Linux kernel, the following vulnerability has been resolved: fbdev: udlfb: add vm_ops to dlfb_ops_mmap to preven...
CVE-2026-43496MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call wit...
CVE-2026-43495HIGH8.8In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: validate port_count against messag...
CVE-2026-43494HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/rds: reset op_nents when zerocopy page pin fail...
CVE-2026-0393MEDIUM6.5The affected product may expose credentials remotely between low privileged visualization users during concurrent login ...
CVE-2026-45255HIGH7.5When bsdinstall or bsdconfig are prompted to scan for nearby Wi-Fi networks, they build up a list of network names and u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now