2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31420MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bridge: mrp: reject zero test interval to avoid OOM...
CVE-2026-31419HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broad...
CVE-2026-31418MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in m...
CVE-2026-31417HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Ad...
CVE-2026-31416MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink heade...
CVE-2026-31415MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6_datagram_send_ctl() Y...
CVE-2026-31414CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper ...
CVE-2026-36923LOW2.7Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php...
CVE-2026-36922LOW2.7Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category...
CVE-2026-36920LOW2.7Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/...
CVE-2026-36919LOW2.7Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/e...
CVE-2026-36874LOW2.7Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.
CVE-2026-36873LOW2.7Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_admin.php.
CVE-2026-36872LOW2.7Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_book.php.
CVE-2026-34476HIGH7.1Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalk...
CVE-2026-6204HIGH7.2LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Bina...
CVE-2026-2728MEDIUM4.8LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig pa...
CVE-2026-35565MEDIUM5.4Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6...
CVE-2026-35337HIGH8.8Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When p...
CVE-2026-4810CRITICAL9.3A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0....
CVE-2026-0234CRITICAL9.1An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms duri...
CVE-2026-0233HIGH8.8A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an ...
CVE-2026-0232MEDIUM4.4A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows admin...
CVE-2026-6168HIGH8.8A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. The affected element is the function setWiFiEasyGuestCfg of ...
CVE-2026-6167HIGH7.3A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now