2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5220 | MEDIUM | 6.4 | — | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa... |
| CVE-2026-5142 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing t... |
| CVE-2026-5138 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information d... |
| CVE-2026-5135 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permis... |
| CVE-2026-58035 | MEDIUM | 4.8 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58034 | MEDIUM | 4.8 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-58031 | MEDIUM | 5.4 | 0.2% | Jul 1, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-14330 | MEDIUM | 5.5 | — | Jul 1, 2026 | Multiple unbounded alloca() calls in the PulseAudio protocol server. |
| CVE-2026-14324 | MEDIUM | 6.5 | — | Jul 1, 2026 | RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. |
| CVE-2026-12374 | MEDIUM | 6.4 | 0.1% | Jul 1, 2026 | Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC ... |
| CVE-2026-53353 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syz... |
| CVE-2026-53352 | MEDIUM | 4.7 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap... |
| CVE-2026-53351 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_... |
| CVE-2026-53350 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing f... |
| CVE-2026-53349 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn exp... |
| CVE-2026-53344 | MEDIUM | 5.5 | 0.1% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->add... |
| CVE-2026-53343 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP st... |
| CVE-2026-53342 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: arm64: mm: call pagetable dtor when freeing hot-rem... |
| CVE-2026-53340 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix clock and pinctrl state inconsistency... |
| CVE-2026-53339 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_... |
| CVE-2026-53338 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Add NULL check for of_reserved_mem_loo... |
| CVE-2026-53337 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL pointer dereference in bond_... |
| CVE-2026-53336 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmem: layouts: onie-tlv: fix hang on unknown types... |
| CVE-2026-53335 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: handle ctx allocation failure D... |
| CVE-2026-53334 | MEDIUM | 5.5 | 0.2% | Jul 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: handle ctx allocation failure Pa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now