2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-93265HIGH7.7In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: tc9563: Fix parsing the integrated Eth...
CVE-2026-93262HIGH7.8In the Linux kernel, the following vulnerability has been resolved: md/raid5-ppl: fix use-after-free in ppl_do_flush() ...
CVE-2026-93260HIGH7.4In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI init errors to prevent ...
CVE-2026-93250HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix use-after-free in vxlan_mdb_flush()...
CVE-2026-93237HIGH7.8In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSMEM_END definition g...
CVE-2026-93229HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nfsd: add missing read barrier to rpc_status_get du...
CVE-2026-93225HIGH7.4In the Linux kernel, the following vulnerability has been resolved: phy: fsl-imx8mq-usb: fix typec switch leak on probe...
CVE-2026-93224HIGH8.1In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix unmatched rn_unregister on failed acce...
CVE-2026-93221HIGH8.1In the Linux kernel, the following vulnerability has been resolved: nfsd: convert nfsd_net boolean flags to unsigned lo...
CVE-2026-88369HIGH7.3zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().
CVE-2026-88368HIGH7.5NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() fu...
CVE-2026-88362HIGH7.5MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted J...
CVE-2026-88361HIGH7.5SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLab...
CVE-2026-88357HIGH7.5nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted ne...
CVE-2026-77581HIGH8.6BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS pr...
CVE-2026-75907HIGH7.5The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID s...
CVE-2026-63203HIGH7.6Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API han...
CVE-2026-56739HIGH8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-...
CVE-2026-56737HIGH8.1phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its pub...
CVE-2026-97362HIGH7.5HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause...
CVE-2026-90959HIGH8.1A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows ...
CVE-2026-82094HIGH7.1IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the s...
CVE-2026-82093HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-81552HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81548HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now