2026 CVE Vulnerabilities

48,018 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-55189HIGH7.7RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP fronten...
CVE-2026-55188HIGH8.2RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an a...
CVE-2026-53322HIGH8.8In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Clean up DMABUFs before disabling functio...
CVE-2026-53303HIGH7.1In the Linux kernel, the following vulnerability has been resolved: f2fs: protect extension_list reading with sb_lock i...
CVE-2026-53300HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: enetc: fix NTMP DMA use-after-free issue The ...
CVE-2026-53296HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: free channels on probe error...
CVE-2026-53294HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channe...
CVE-2026-53290HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/eustall: Fix drm_dev_put called before strea...
CVE-2026-53286HIGH7.8In the Linux kernel, the following vulnerability has been resolved: idpf: fix double free and use-after-free in aux dev...
CVE-2026-53284HIGH7.5In the Linux kernel, the following vulnerability has been resolved: btrfs: only release the dirty pages io tree after s...
CVE-2026-53281HIGH8.8In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Avoid NULL pointer dereference or refco...
CVE-2026-52784HIGH8.8OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET...
CVE-2026-52783HIGH8.2OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages mo...
CVE-2026-49991HIGH8.6RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject pe...
CVE-2026-47193HIGH7.5OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint...
CVE-2026-32833HIGH8.8Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authe...
CVE-2026-47220HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38...
CVE-2026-13372HIGH7.2Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026...
CVE-2026-56876HIGH8.6extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file contain...
CVE-2026-55441HIGH8.6mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil...
CVE-2026-54341HIGH7.5Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload ...
CVE-2026-48743HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-48706HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-48497HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-48044HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now