2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-19036HIGH7.3A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp...
CVE-2026-68481HIGH7.5In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec...
CVE-2026-57818HIGH8.1A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via c...
CVE-2026-19035HIGH7.3A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of ...
CVE-2026-65432HIGH7.5Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. Ho...
CVE-2026-64958HIGH7.5An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF...
CVE-2026-57819HIGH7.5Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" co...
CVE-2026-57817HIGH8.1The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in th...
CVE-2026-54225HIGH7.5Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4....
CVE-2026-19034HIGH7.3A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_s...
CVE-2026-55978HIGH8.4An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an ...
CVE-2026-64601HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant us...
CVE-2026-64599HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_cry...
CVE-2026-64598HIGH8.8In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc()...
CVE-2026-64588HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakl...
CVE-2026-64587HIGH7In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before...
CVE-2026-64586HIGH8.8In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device remo...
CVE-2026-64585HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing net...
CVE-2026-64584HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before ...
CVE-2026-64583HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake...
CVE-2026-19021HIGH7.3A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by thi...
CVE-2026-19010HIGH7.3A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag...
CVE-2026-19009HIGH7.3A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core...
CVE-2026-18649HIGH7.5A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements d...
CVE-2026-18597HIGH8.5The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now