2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5220MEDIUM6.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa...
CVE-2026-5142MEDIUM6.5A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing t...
CVE-2026-5138MEDIUM4.3A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information d...
CVE-2026-5135MEDIUM6.5A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permis...
CVE-2026-58035MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58034MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-58031MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2026-14330MEDIUM5.5Multiple unbounded alloca() calls in the PulseAudio protocol server.
CVE-2026-14324MEDIUM6.5RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.
CVE-2026-12374MEDIUM6.4Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC ...
CVE-2026-53353MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syz...
CVE-2026-53352MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: signal: clear JOBCTL_PENDING_MASK for caller in zap...
CVE-2026-53351MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_...
CVE-2026-53350MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing f...
CVE-2026-53349MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn exp...
CVE-2026-53344MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->add...
CVE-2026-53343MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP st...
CVE-2026-53342MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: mm: call pagetable dtor when freeing hot-rem...
CVE-2026-53340MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix clock and pinctrl state inconsistency...
CVE-2026-53339MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: qcom-cci: Fix NULL pointer dereference in cci_...
CVE-2026-53338MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: airoha: Add NULL check for of_reserved_mem_loo...
CVE-2026-53337MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL pointer dereference in bond_...
CVE-2026-53336MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvmem: layouts: onie-tlv: fix hang on unknown types...
CVE-2026-53335MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/damon/lru_sort: handle ctx allocation failure D...
CVE-2026-53334MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/damon/reclaim: handle ctx allocation failure Pa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now