2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-93786HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The V...
CVE-2026-93782HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhos...
CVE-2026-93543HIGH7.4An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an...
CVE-2026-93288HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period...
CVE-2026-93287HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the...
CVE-2026-93284HIGH8.8In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migrat...
CVE-2026-91160HIGH8.2OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers...
CVE-2026-91123HIGH7.2Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src tra...
CVE-2026-91122HIGH8.7Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placehol...
CVE-2026-88390HIGH7.7An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted Java...
CVE-2026-88382HIGH7.5hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate pars...
CVE-2026-88376HIGH7.5Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A speci...
CVE-2026-88373HIGH7.5libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL()...
CVE-2026-88372HIGH7.5libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) ...
CVE-2026-79764HIGH7.7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0...
CVE-2026-63498HIGH8.7Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_t...
CVE-2026-63493HIGH8.6Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with ...
CVE-2026-62368HIGH8.1Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can st...
CVE-2026-56744HIGH8.7`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@b...
CVE-2026-56738HIGH8.5phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `IN...
CVE-2026-96750HIGH7.1MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell wh...
CVE-2026-96744HIGH7.1Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integrat...
CVE-2026-93282HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL ...
CVE-2026-93280HIGH8.8In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes ag...
CVE-2026-93277HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing comma...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now