2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40450MEDIUM6.6Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and...
CVE-2026-40449MEDIUM6.6Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in S...
CVE-2026-40448MEDIUM5.3Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large ...
CVE-2026-22754HIGH7.5Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=...
CVE-2026-22753HIGH7.5Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMat...
CVE-2026-22748MEDIUM6.5Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder  or NimbusRea...
CVE-2026-22747HIGH8.1Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509...
CVE-2026-22746LOW3.7Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or ...
CVE-2026-40451MEDIUM6.1DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which all...
CVE-2026-6835MEDIUM6.1The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to ...
CVE-2026-6834HIGH7.1The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arb...
CVE-2026-6833HIGH7.1The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbi...
CVE-2026-6416MEDIUM4.9Tanium addressed an uncontrolled resource consumption vulnerability in Interact.
CVE-2026-6408LOW2.7Tanium addressed an information disclosure vulnerability in Tanium Server.
CVE-2026-6392LOW2.7Tanium addressed an information disclosure vulnerability in Threat Response.
CVE-2026-6386MEDIUM6.2In order to apply a particular protection key to an address range, the kernel must update the corresponding page table e...
CVE-2026-5398HIGH8.4The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal ...
CVE-2026-41458HIGH8.2OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows u...
CVE-2026-41457MEDIUM6.9OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that a...
CVE-2026-41146HIGH8.7facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_jso...
CVE-2026-41145HIGH8.2MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04...
CVE-2026-40344HIGH8.2MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04...
CVE-2026-41304CRITICAL9.8WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the Clo...
CVE-2026-41144CRITICAL9.8F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applicati...
CVE-2026-41136MEDIUM5.3free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now