2026 CVE Vulnerabilities

69,550 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0120CRITICAL9.8In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execu...
CVE-2026-0119MEDIUM6.8In usim_SendMCCMNCIndMsg of usim_Registration.c, there is a possible out of bounds write due to memory corruption. This ...
CVE-2026-0118HIGH8.4In oobconfig, there is a possible bypass of carrier restrictions due to a logic error. This could lead to local escalati...
CVE-2026-0117HIGH8.4In mfc_dec_dqbuf of mfc_dec_v4l2.c, there is a possible out of bounds write due to an incorrect bounds check. This could...
CVE-2026-0116CRITICAL9.8In __mfc_handle_released_buf of mfc_core_isr.c, there is a possible out of bounds write due to a missing bounds check. T...
CVE-2026-0115LOW2.1In Trusted Execution Environment, there is a possible key leak due to side channel information disclosure. This could le...
CVE-2026-0114CRITICAL9.8In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execu...
CVE-2026-0113CRITICAL9.8In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This...
CVE-2026-0112HIGH7.4In vpu_open_inst of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local es...
CVE-2026-0111CRITICAL9.8In ns_GetUserData of ns_SmscbUtilities.c, there is a possible out of bounds write due to an incorrect bounds check. This...
CVE-2026-0110CRITICAL9.8In MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, there is a possible EoP due to memory corruption. This could lead to remote ...
CVE-2026-0109HIGH7.5In dhd_tcpdata_info_get of dhd_ip.c, there is a possible Denial of Service due to a precondition check failure. This cou...
CVE-2026-0108MEDIUM4The register protection of the PowerVR GPU is incorrectly configured. This could lead to local information disclosure wi...
CVE-2026-0107HIGH8.4In gmc_ddr_handle_mba_mr_req of gmc_mba_ddr.c, there is a possible escalation of privileges due to a confused deputy. Th...
CVE-2026-3582MEDIUM4.3An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user w...
CVE-2026-2713HIGH7.8IBM Trusteer Rapport installer 3.5.2309.290 IBM Trusteer Rapport could allow a local attacker to execute arbitrary code ...
CVE-2026-2266MEDIUM5.4An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cros...
CVE-2026-29793CRITICAL9.8Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to...
CVE-2026-29792CRITICAL9.8Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to ...
CVE-2026-29177MEDIUM5.4Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vu...
CVE-2026-29176MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored XSS vulnerability exists in the Commerce...
CVE-2026-29175MEDIUM5.4Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce ...
CVE-2026-29174HIGH8.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in ...
CVE-2026-29173MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when...
CVE-2026-29172HIGH8.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL In...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now