2026 CVE Vulnerabilities
64,678 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45254 | MEDIUM | 6.5 | 0.2% | May 21, 2026 | In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key ... |
| CVE-2026-45253 | HIGH | 8.4 | 0.2% | May 21, 2026 | ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a... |
| CVE-2026-45252 | MEDIUM | 5.5 | 0.3% | May 21, 2026 | When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace ... |
| CVE-2026-45251 | HIGH | 7.8 | 0.2% | May 21, 2026 | A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. B... |
| CVE-2026-42396 | MEDIUM | 6.5 | 0.4% | May 21, 2026 | Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail |
| CVE-2026-42002 | HIGH | 7.5 | 0.3% | May 21, 2026 | Concurrency and locking defects in GSS-TSIG |
| CVE-2026-42001 | HIGH | 7.5 | 0.4% | May 21, 2026 | Insufficient Validation of Autoprimary SOA Queries |
| CVE-2026-42000 | HIGH | 8.6 | 0.2% | May 21, 2026 | Insufficient Validation of Names During AXFR |
| CVE-2026-41999 | MEDIUM | 4.8 | 0.1% | May 21, 2026 | Incorrect Behaviour of Views with TCP PROXY Requests |
| CVE-2026-39461 | HIGH | 8.8 | 0.2% | May 21, 2026 | libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for ... |
| CVE-2026-28764 | HIGH | 7.8 | 0.2% | May 21, 2026 | A heap-based buffer overflow vulnerability exists in the LXF element parsing functionality of MediaInfoLib (version(s): ... |
| CVE-2026-9157 | HIGH | 8.6 | 0.1% | May 21, 2026 | Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remo... |
| CVE-2026-7837 | LOW | 3.7 | 0.2% | May 21, 2026 | A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-pr... |
| CVE-2026-5434 | MEDIUM | 5.9 | 0.2% | May 21, 2026 | Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An atta... |
| CVE-2026-5433 | CRITICAL | 9.1 | 0.9% | May 21, 2026 | Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could ... |
| CVE-2026-4858 | CRITICAL | 9.9 | 0.2% | May 21, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration ... |
| CVE-2026-45250 | HIGH | 7.8 | 0.4% | May 21, 2026 | The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is ... |
| CVE-2026-44075 | LOW | 3.7 | 0.3% | May 21, 2026 | A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch... |
| CVE-2026-44074 | LOW | 3.7 | 0.3% | May 21, 2026 | Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when mu... |
| CVE-2026-44071 | LOW | 3.7 | 0.3% | May 21, 2026 | Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at ru... |
| CVE-2026-44057 | LOW | 3.1 | 0.2% | May 21, 2026 | A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code pat... |
| CVE-2026-27393 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-27349 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint all... |
| CVE-2026-22880 | MEDIUM | 6.1 | 0.1% | May 21, 2026 | Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO aut... |
| CVE-2026-7836 | LOW | 3.1 | 0.3% | May 21, 2026 | An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now