2026 CVE Vulnerabilities

49,078 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46447HIGH7.7OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info o...
CVE-2026-22055HIGH8.8Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low p...
CVE-2026-22054HIGH8.8Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with l...
CVE-2026-10771HIGH7.3A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-...
CVE-2026-50033HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-44682HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-44609HIGH7.3Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock D...
CVE-2026-42061HIGH7.3Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected...
CVE-2026-8889HIGH7.5Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) an...
CVE-2026-8888HIGH7.5Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as J...
CVE-2026-8881HIGH7.5Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES...
CVE-2026-8879HIGH7.5Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scri...
CVE-2026-8878HIGH7.5Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated ...
CVE-2026-8876HIGH7.3Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These key...
CVE-2026-8874HIGH7.1Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules ...
CVE-2026-7888HIGH8.4Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and ...
CVE-2026-46273HIGH8.6In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS So...
CVE-2026-46271HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link ...
CVE-2026-46270HIGH8.4In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_...
CVE-2026-46267HIGH7.8In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freein...
CVE-2026-46265HIGH7.5In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc i...
CVE-2026-46264HIGH8.8In the Linux kernel, the following vulnerability has been resolved: drm/xe/pf: Fix sysfs initialization In case of dev...
CVE-2026-46263HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds stream encoder i...
CVE-2026-46260HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node()...
CVE-2026-46259HIGH7.8In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading rea...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now