2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-41418MEDIUM5.34ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumerat...
CVE-2026-42042MEDIUM5.4Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF t...
CVE-2026-42041MEDIUM6.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulne...
CVE-2026-42037MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart construc...
CVE-2026-42036MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream...
CVE-2026-42034MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies,...
CVE-2026-41898MEDIUM5.3rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampo...
CVE-2026-41322MEDIUM5.3@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resource...
CVE-2026-41411MEDIUM6.6Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's ta...
CVE-2026-41079MEDIUM5.4OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a ...
CVE-2026-41067MEDIUM6.1Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a...
CVE-2026-30368MEDIUM5.4A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersona...
CVE-2026-42095MEDIUM4bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL.
CVE-2026-31672MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lifetime USB drivers b...
CVE-2026-31671MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_report() struct ...
CVE-2026-31670MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill ev...
CVE-2026-31664MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() ...
CVE-2026-31661MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: Fix dma_free_coherent() size dma_a...
CVE-2026-31660MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: allocate rx skb before consuming bytes ...
CVE-2026-31658MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: altera-tse: fix skb leak on DMA mapping error ...
CVE-2026-31655MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock ...
CVE-2026-31654MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/vma: fix memory leak in __mmap_region() commit ...
CVE-2026-31653MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: dealloc repeat_call_control if damo...
CVE-2026-31651MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix NULL-deref on disconnect Make sur...
CVE-2026-31647MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: idpf: fix PREEMPT_RT raw/bh spinlock nesting for as...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now