2026 CVE Vulnerabilities

48,948 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-35233MEDIUM4.4An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link f...
CVE-2026-26461MEDIUM6.5A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticate...
CVE-2026-21996MEDIUM5.5An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an intege...
CVE-2026-7587MEDIUM4.3A vulnerability has been found in Open5GS up to 2.7.7. This vulnerability affects the function amf_nsmf_pdusession_handl...
CVE-2026-7586MEDIUM4.3A weakness has been identified in Open5GS up to 2.7.7. Affected is the function ogs_id_get_value of the file /src/amf/nu...
CVE-2026-7585MEDIUM4.3A vulnerability was determined in Open5GS up to 2.7.7. The impacted element is the function amf_nudm_sdm_handle_provisio...
CVE-2026-42481MEDIUM5.5Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can b...
CVE-2026-42480MEDIUM5.5A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology...
CVE-2026-42475MEDIUM6.5SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHe...
CVE-2026-42474MEDIUM6.5SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `data` array to the data function in BuildHe...
CVE-2026-37505MEDIUM4.9SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort para...
CVE-2026-37503MEDIUM4.8Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade u...
CVE-2026-23866MEDIUM4.3Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and ...
CVE-2026-23863MEDIUM6.5An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously f...
CVE-2026-7583MEDIUM4.3A flaw has been found in Open5GS up to 2.7.7. This issue affects the function bsf_sess_find_by_ipv6prefix of the file /s...
CVE-2026-43505MEDIUM6.5An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Be...
CVE-2026-43504MEDIUM6.5An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Be...
CVE-2026-43054MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: target: tcm_loop: Drain commands in target_re...
CVE-2026-43053MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: xfs: close crash window in attr dabtree inactivatio...
CVE-2026-43046MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: reject root items with drop_progress and zer...
CVE-2026-43045MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mshv: Fix error handling in mshv_region_pin The cu...
CVE-2026-43043MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: af-alg - fix NULL pointer dereference in sc...
CVE-2026-43041MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: qrtr: replace qrtr_tx_flow radix_tree with xar...
CVE-2026-43036MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_of...
CVE-2026-43035MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to init...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now