2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-20004HIGH7.4A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust...
CVE-2026-1917MEDIUM4.3Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypa...
CVE-2026-4363LOW3.7GitLab has remediated an issue in GitLab EE affecting all versions from 18.1 before 18.8.7, 18.9 before 18.9.3, and 18.1...
CVE-2026-3126——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-33268MEDIUM6.9Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmwar...
CVE-2026-26830CRITICAL9.8pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGe...
CVE-2026-23514MEDIUM6.5Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerabili...
CVE-2026-4816MEDIUM5.4A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows a...
CVE-2026-4815HIGH8.8A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve,...
CVE-2026-3591MEDIUM5.4A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a spec...
CVE-2026-3119MEDIUM6.5Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affec...
CVE-2026-3104HIGH7.5A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This is...
CVE-2026-28529HIGH7.8cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/cr...
CVE-2026-1519HIGH7.5If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume e...
CVE-2026-4761HIGH7.5When a certificate and its private key are installed in the Windows machine certificate store using Network and Security...
CVE-2026-4760HIGH7.7From Panorama Web HMI, an attacker can gain read access to certain Web HMI server files, if he knows their paths and if ...
CVE-2026-31788HIGH8.2In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: restrict usage in unprivileged domU T...
CVE-2026-23395HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRE...
CVE-2026-23394MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: af_unix: Give up GC if MSG_PEEK intervened. Igor U...
CVE-2026-23393HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bridge: cfm: Fix race condition in peer_mep deletio...
CVE-2026-23392HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release flowtable after rcu g...
CVE-2026-23391HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_CT: drop pending enqueued packets on ...
CVE-2026-23390HIGH7.8In the Linux kernel, the following vulnerability has been resolved: tracing/dma: Cap dma_map_sg tracepoint arrays to pr...
CVE-2026-23389MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice...
CVE-2026-23388HIGH7.1In the Linux kernel, the following vulnerability has been resolved: Squashfs: check metadata block offset is within ran...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now