2026 CVE Vulnerabilities
64,982 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5749 | HIGH | 8.7 | 0.3% | Apr 22, 2026 | Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain ... |
| CVE-2026-41651 | HIGH | 8.8 | 0.5% | Apr 22, 2026 | PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, ... |
| CVE-2026-33611 | MEDIUM | 4.9 | 0.4% | Apr 22, 2026 | An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data,... |
| CVE-2026-33610 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondar... |
| CVE-2026-33609 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domai... |
| CVE-2026-33608 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes sai... |
| CVE-2026-33602 | HIGH | 8.2 | 0.7% | Apr 22, 2026 | A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, trig... |
| CVE-2026-33599 | HIGH | 8.1 | 0.3% | Apr 22, 2026 | A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via eith... |
| CVE-2026-33598 | CRITICAL | 9.1 | 1.1% | Apr 22, 2026 | A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddres... |
| CVE-2026-33597 | HIGH | 7.5 | 0.3% | Apr 22, 2026 | PRSD detection denial of service |
| CVE-2026-33596 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by... |
| CVE-2026-33595 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 conn... |
| CVE-2026-33594 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH bac... |
| CVE-2026-33593 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query. |
| CVE-2026-33254 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSd... |
| CVE-2026-31530 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix use after free of parent_port in cxl_... |
| CVE-2026-31529 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix leakage in __construct_region() Fa... |
| CVE-2026-31528 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf: Make sure to use pmu_ctx->pmu for groups Oli... |
| CVE-2026-31527 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use generic driver_override ... |
| CVE-2026-31526 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix exception exit lock checking for subprogs ... |
| CVE-2026-31525 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix undefined behavior in interpreter sdiv/smo... |
| CVE-2026-31524 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: asus: avoid memory leak in asus_report_fixup()... |
| CVE-2026-31523 | MEDIUM | 4.7 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A us... |
| CVE-2026-31522 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: avoid memory leak in magicmouse_re... |
| CVE-2026-31521 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: module: Fix kernel panic when a symbol st_shndx is ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now