2026 CVE Vulnerabilities

64,982 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35352HIGH7A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility cre...
CVE-2026-35351MEDIUM4.2The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries....
CVE-2026-35350MEDIUM6.6The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. Wh...
CVE-2026-35349HIGH7.7A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementat...
CVE-2026-35348MEDIUM5.5The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs co...
CVE-2026-35347MEDIUM4.4The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison...
CVE-2026-35346LOW3.3The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. Th...
CVE-2026-35345MEDIUM5.3A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when usin...
CVE-2026-35344LOW3.3The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result...
CVE-2026-35343LOW3.3The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is speci...
CVE-2026-35342LOW3.3The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp,...
CVE-2026-35341HIGH7.1A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. Wh...
CVE-2026-35340MEDIUM5.5A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit co...
CVE-2026-35339MEDIUM5.5The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple...
CVE-2026-35338HIGH7.3A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. Th...
CVE-2026-32885CRITICAL9.1DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2...
CVE-2026-1660MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2026-30139MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before versi...
CVE-2026-35548HIGH8.5An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix ...
CVE-2026-6862MEDIUM5.5A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that ...
CVE-2026-6861HIGH7.1A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially craf...
CVE-2026-6859HIGH8.8A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from...
CVE-2026-6356CRITICAL9.6A vulnerability in the web application allows standard users to escalate their privileges to those of a super administra...
CVE-2026-6355MEDIUM6.5A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across differen...
CVE-2026-5750HIGH7.6An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated us...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now