2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20004 | HIGH | 7.4 | — | Mar 25, 2026 | A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust... |
| CVE-2026-1917 | MEDIUM | 4.3 | 0.2% | Mar 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypa... |
| CVE-2026-4363 | LOW | 3.7 | 0.1% | Mar 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.1... |
| CVE-2026-3126 | — | — | — | Mar 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-33268 | MEDIUM | 6.9 | 0.3% | Mar 25, 2026 | Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmwar... |
| CVE-2026-26830 | CRITICAL | 9.8 | 2.5% | Mar 25, 2026 | pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGe... |
| CVE-2026-23514 | MEDIUM | 6.5 | 1.0% | Mar 25, 2026 | Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerabili... |
| CVE-2026-4816 | MEDIUM | 5.4 | 0.1% | Mar 25, 2026 | A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows a... |
| CVE-2026-4815 | HIGH | 8.8 | 0.2% | Mar 25, 2026 | A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve,... |
| CVE-2026-3591 | MEDIUM | 5.4 | 0.4% | Mar 25, 2026 | A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a spec... |
| CVE-2026-3119 | MEDIUM | 6.5 | 0.6% | Mar 25, 2026 | Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affec... |
| CVE-2026-3104 | HIGH | 7.5 | 0.7% | Mar 25, 2026 | A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This is... |
| CVE-2026-28529 | HIGH | 7.8 | 0.1% | Mar 25, 2026 | cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/cr... |
| CVE-2026-1519 | HIGH | 7.5 | 1.6% | Mar 25, 2026 | If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume e... |
| CVE-2026-4761 | HIGH | 7.5 | 0.1% | Mar 25, 2026 | When a certificate and its private key are installed in the Windows machine certificate store using Network and Security... |
| CVE-2026-4760 | HIGH | 7.7 | 0.3% | Mar 25, 2026 | From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if ... |
| CVE-2026-31788 | HIGH | 8.2 | 0.2% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU T... |
| CVE-2026-23395 | HIGH | 8.8 | 0.2% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRE... |
| CVE-2026-23394 | MEDIUM | 4.7 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Give up GC if MSG_PEEK intervened. Igor U... |
| CVE-2026-23393 | HIGH | 7.8 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletio... |
| CVE-2026-23392 | HIGH | 7.8 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flowtable after rcu g... |
| CVE-2026-23391 | HIGH | 7.8 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_CT: drop pending enqueued packets on ... |
| CVE-2026-23390 | HIGH | 7.8 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing/dma: Cap dma_map_sg tracepoint arrays to pr... |
| CVE-2026-23389 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice... |
| CVE-2026-23388 | HIGH | 7.1 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within ran... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now