2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31693HIGH7.8In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In se...
CVE-2026-1493MEDIUM5.4LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the para...
CVE-2026-31787HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting pri...
CVE-2026-31786HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c Th...
CVE-2026-31692MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check f...
CVE-2026-6498MEDIUM5.3The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in ve...
CVE-2026-42800MEDIUM5.3NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Mani...
CVE-2026-41016MEDIUM5.9Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certif...
CVE-2026-42799CRITICAL9.8Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associa...
CVE-2026-42512HIGH8.1As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. ...
CVE-2026-39457HIGH7.8When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whethe...
CVE-2026-35547HIGH8.1When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali...
CVE-2026-22070CRITICAL9.8ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
CVE-2026-7164HIGH7.5Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a ...
CVE-2026-7270HIGH7.8An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data t...
CVE-2026-6870MEDIUM5.5GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6869MEDIUM5.5WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6867MEDIUM5.5SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6538MEDIUM5.5BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6537MEDIUM5.5ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6536MEDIUM5.5DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4
CVE-2026-6535MEDIUM5.5Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6534MEDIUM5.5USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6533MEDIUM5.5Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6532MEDIUM5.5Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now