2026 CVE Vulnerabilities
66,324 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31402 | CRITICAL | 9.8 | 0.5% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix heap overflow in NFSv4.0 LOCK replay cach... |
| CVE-2026-31401 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: bpf: prevent buffer overflow in hid_hw_request... |
| CVE-2026-31400 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix cache_request leak in cache_release Wh... |
| CVE-2026-31399 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvdimm/bus: Fix potential use after free in asynchr... |
| CVE-2026-31398 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix incorrect pte restoration for lazyfree... |
| CVE-2026-31397 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: fix use of NULL folio in move_pages... |
| CVE-2026-31396 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock ... |
| CVE-2026-31395 | HIGH | 7.1 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async e... |
| CVE-2026-31394 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: mac80211: fix crash in ieee80211_chan_bw_change for... |
| CVE-2026-31393 | HIGH | 8.1 | 0.3% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload l... |
| CVE-2026-31392 | HIGH | 8.1 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix krb5 mount with username option C... |
| CVE-2026-31391 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - Fix OOM ->tfm_count leak I... |
| CVE-2026-31390 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix memory leak in xe_vm_madvise_ioctl Whe... |
| CVE-2026-31389 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: fix use-after-free on controller registration ... |
| CVE-2026-27124 | MEDIUM | 6.1 | 0.2% | Apr 3, 2026 | FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, while testing the GitHubProvide... |
| CVE-2026-25118 | HIGH | 7.5 | 0.4% | Apr 3, 2026 | immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich applica... |
| CVE-2026-25044 | HIGH | 8.8 | 0.5% | Apr 3, 2026 | Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step executes user-provided c... |
| CVE-2026-25043 | HIGH | 7.5 | 0.3% | Apr 3, 2026 | Budibase is an open-source low-code platform. Prior to version 3.23.25, a business logic vulnerability exists in Budibas... |
| CVE-2026-23475 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: fix statistics allocation The controller per-... |
| CVE-2026-23474 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: mtd: Avoid boot crash in RedBoot partition table pa... |
| CVE-2026-23473 | — | — | — | Apr 3, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-23472 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: serial: core: fix infinite loop in handle_tx() for ... |
| CVE-2026-23471 | — | — | — | Apr 3, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-23470 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fix deadlock in soft reset sequenc... |
| CVE-2026-23469 | MEDIUM | 4.7 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Synchronize interrupts before susp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now