2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7865HIGH7.4A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argume...
CVE-2026-7846LOW2.6A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the...
CVE-2026-7845LOW2.6A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.toby...
CVE-2026-7844MEDIUM6.3A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function...
CVE-2026-7412HIGH8.6In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validat...
CVE-2026-7411CRITICAL10In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTT...
CVE-2026-6907MEDIUM5.3An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erron...
CVE-2026-5766MEDIUM6.3An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-...
CVE-2026-43073MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86-64: rename misleadingly named '__copy_user_noca...
CVE-2026-43072MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vc4: platform_get_irq_byname() returns an int ...
CVE-2026-43071CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two ...
CVE-2026-43070HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register ID for BPF_END value tracking ...
CVE-2026-43069MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ll: Fix firmware leak on error path ...
CVE-2026-43068MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocate block from corrupted group in ...
CVE-2026-43067CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks f...
CVE-2026-43066MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: fix iloc.bh leak in ext4_fc_replay_inode() er...
CVE-2026-43065MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: always drain queued discard work in ext4_mb_r...
CVE-2026-43064MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix not releasing workqueue on .re...
CVE-2026-43063HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: don't irele after failing to iget in xfs_attri...
CVE-2026-43062HIGH7.1In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix type confusion in l2cap_ecred...
CVE-2026-43061MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix TX deadlock when using DMA `dmae...
CVE-2026-43060HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: drop pending enqueued packets on...
CVE-2026-43059HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix list corruption and UAF in com...
CVE-2026-39103MEDIUM5.5Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to caus...
CVE-2026-35192MEDIUM6.5An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now