2026 CVE Vulnerabilities

64,678 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45254MEDIUM6.5In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key ...
CVE-2026-45253HIGH8.4ptrace(PT_SC_REMOTE) failed to properly validate parameters for the syscall(2) and __syscall(2) meta-system calls. As a...
CVE-2026-45252MEDIUM5.5When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace ...
CVE-2026-45251HIGH7.8A file descriptor can be closed while a thread is blocked in a poll(2) or select(2) call waiting for that descriptor. B...
CVE-2026-42396MEDIUM6.5Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
CVE-2026-42002HIGH7.5Concurrency and locking defects in GSS-TSIG
CVE-2026-42001HIGH7.5Insufficient Validation of Autoprimary SOA Queries
CVE-2026-42000HIGH8.6Insufficient Validation of Names During AXFR
CVE-2026-41999MEDIUM4.8Incorrect Behaviour of Views with TCP PROXY Requests
CVE-2026-39461HIGH8.8libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for ...
CVE-2026-28764HIGH7.8A heap-based buffer overflow vulnerability exists in the LXF element parsing functionality of MediaInfoLib (version(s): ...
CVE-2026-9157HIGH8.6Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remo...
CVE-2026-7837LOW3.7A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-pr...
CVE-2026-5434MEDIUM5.9Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An atta...
CVE-2026-5433CRITICAL9.1Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could ...
CVE-2026-4858CRITICAL9.9Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration ...
CVE-2026-45250HIGH7.8The setcred(2) system call is only available to privileged users. However, before the privilege level of the caller is ...
CVE-2026-44075LOW3.7A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch...
CVE-2026-44074LOW3.7Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when mu...
CVE-2026-44071LOW3.7Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at ru...
CVE-2026-44057LOW3.1A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code pat...
CVE-2026-27393MEDIUM5.3Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2026-27349MEDIUM4.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint all...
CVE-2026-22880MEDIUM6.1Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO aut...
CVE-2026-7836LOW3.1An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now