2026 CVE Vulnerabilities
47,646 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26378 | MEDIUM | 5.4 | 0.3% | Jun 3, 2026 | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file ... |
| CVE-2026-46272 | MEDIUM | 4.7 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysf... |
| CVE-2026-46269 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL pointer dereference... |
| CVE-2026-46268 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning conditi... |
| CVE-2026-46262 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_xcvr: Revert fix missing lock in fsl_xcvr... |
| CVE-2026-46261 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: wpcm-fiu: Fix potential NULL pointer dereferen... |
| CVE-2026-46258 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpio: cdev: Avoid NULL dereference in linehandle_cr... |
| CVE-2026-46257 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sp804: Fix an Oops when r... |
| CVE-2026-46256 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFS/localio: prevent direct reclaim recursion into ... |
| CVE-2026-46255 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: don't explicitly disable clock... |
| CVE-2026-46254 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: AppArmor: Allow apparmor to handle unaligned dfa ta... |
| CVE-2026-46252 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: regulator: core: fix locking in regulator_resolve_s... |
| CVE-2026-46249 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: Fix PF driver crash with kexec kernel... |
| CVE-2026-46248 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: clear stale link mapping of ahvif->li... |
| CVE-2026-46247 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gfx3d: add parent to parent request map ... |
| CVE-2026-46245 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dc_link NULL handling in HPD i... |
| CVE-2026-39107 | MEDIUM | 6.3 | 0.3% | Jun 3, 2026 | A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails... |
| CVE-2026-36618 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS ... |
| CVE-2026-36616 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver credentials including a RADIUS s... |
| CVE-2026-36615 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 exposes an undocumented /agileconfigreset endpoint that returns... |
| CVE-2026-36613 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 returns 128 bytes of uninitialized internal buffer contents whe... |
| CVE-2026-36612 | MEDIUM | 6.4 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 enables WPS 2.0 by default with a weak lockout policy (60-secon... |
| CVE-2026-36610 | MEDIUM | 5.9 | 0.1% | Jun 3, 2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 transmits DDNS credentials over plaintext HTTP with only Base64... |
| CVE-2026-36605 | MEDIUM | 6.5 | 0.2% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 is vulnerable to a HTTP denial of service via a low numb... |
| CVE-2026-36604 | MEDIUM | 6.5 | 0.3% | Jun 3, 2026 | Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS reb... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now