2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35350 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. Wh... |
| CVE-2026-35348 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs co... |
| CVE-2026-35347 | MEDIUM | 4.4 | 0.1% | Apr 22, 2026 | The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison... |
| CVE-2026-35345 | MEDIUM | 5.3 | 0.1% | Apr 22, 2026 | A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when usin... |
| CVE-2026-35340 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit co... |
| CVE-2026-35339 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple... |
| CVE-2026-1660 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2026-30139 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before versi... |
| CVE-2026-6862 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that ... |
| CVE-2026-6355 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across differen... |
| CVE-2026-33611 | MEDIUM | 4.9 | 0.4% | Apr 22, 2026 | An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data,... |
| CVE-2026-33609 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domai... |
| CVE-2026-33596 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by... |
| CVE-2026-31529 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix leakage in __construct_region() Fa... |
| CVE-2026-31526 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix exception exit lock checking for subprogs ... |
| CVE-2026-31524 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: asus: avoid memory leak in asus_report_fixup()... |
| CVE-2026-31523 | MEDIUM | 4.7 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvme-pci: ensure we're polling a polled queue A us... |
| CVE-2026-31522 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: magicmouse: avoid memory leak in magicmouse_re... |
| CVE-2026-31521 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: module: Fix kernel panic when a symbol st_shndx is ... |
| CVE-2026-31520 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: apple: avoid memory leak in apple_report_fixup... |
| CVE-2026-31519 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol ... |
| CVE-2026-31518 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: esp: fix skb leak with espintcp and async crypto W... |
| CVE-2026-31517 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix skb_put() panic on non-linear skb ... |
| CVE-2026-31515 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: af_key: validate families in pfkey_send_migrate() ... |
| CVE-2026-31514 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: erofs: set fileio bio failed in short read case Fo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now