2026 CVE Vulnerabilities

66,201 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-21382HIGH7.8Memory Corruption when handling power management requests with improperly sized input/output buffers.
CVE-2026-21381HIGH7.5Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware...
CVE-2026-21380HIGH7.8Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
CVE-2026-21378HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor...
CVE-2026-21376HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor...
CVE-2026-21375HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21374HIGH7.8Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio...
CVE-2026-21373HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21372HIGH7.8Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations.
CVE-2026-21371HIGH7.8Memory Corruption when retrieving output buffer with insufficient size validation.
CVE-2026-21367HIGH7.5Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
CVE-2026-5664——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-30078. Reason: This candidate is a ...
CVE-2026-5663CRITICAL9.8A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEn...
CVE-2026-5661MEDIUM5.5A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handle...
CVE-2026-34897MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi...
CVE-2026-34885HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi...
CVE-2026-33540HIGH7.5Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mod...
CVE-2026-33510HIGH8.8Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been disco...
CVE-2026-33406MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-33404MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-33403MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-32602MEDIUM4.2Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnera...
CVE-2026-31153MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Bynder before 12 January 2026 allows attackers to execute arbitrary...
CVE-2026-31151CRITICAL9.8An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the appl...
CVE-2026-31150MEDIUM4.3Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now