2026 CVE Vulnerabilities
50,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45867 | HIGH | 7.8 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: power: supply: act8945a: Fix use-after-free in powe... |
| CVE-2026-45866 | HIGH | 7.8 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: serial: caif: fix use-after-free in caif_serial ldi... |
| CVE-2026-45862 | HIGH | 7.8 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Flush cache for PASID table before usin... |
| CVE-2026-45861 | HIGH | 7.8 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix slab-use-after-free in qd_put Commit a47... |
| CVE-2026-45860 | HIGH | 7.5 | 0.7% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection cl... |
| CVE-2026-45859 | HIGH | 7.5 | 0.6% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: do shared-unconfirmed c... |
| CVE-2026-45856 | HIGH | 7.1 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Validate wqe_size before using it in i... |
| CVE-2026-45853 | HIGH | 7.8 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Use kvfree instead of kfree in amdgpu_g... |
| CVE-2026-45852 | HIGH | 7.8 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix double free in rxe_srq_from_init In ... |
| CVE-2026-45851 | HIGH | 7.1 | 0.2% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: efi: Fix reservation of unaccepted memory table Th... |
| CVE-2026-3623 | HIGH | 7.8 | 0.2% | May 27, 2026 | IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged acces... |
| CVE-2026-3366 | HIGH | 7.5 | 0.6% | May 27, 2026 | IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, ... |
| CVE-2026-38427 | HIGH | 7.3 | 0.5% | May 27, 2026 | An issue in fetch_jpg() in xdrv_10_scripter.ino in Tasmota through 15.3.0.3 allows a remote attacker to cause heap buffe... |
| CVE-2026-38426 | HIGH | 7.3 | 0.6% | May 27, 2026 | Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary cod... |
| CVE-2026-38422 | HIGH | 7.3 | 0.8% | May 27, 2026 | Buffer Overflow vulnerability in arendst Tasmota v.15.3.0.3 and before allows a remote attacker to execute arbitrary cod... |
| CVE-2026-36540 | HIGH | 7.3 | 1.5% | May 27, 2026 | Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi end... |
| CVE-2026-36539 | HIGH | 7.3 | 0.4% | May 27, 2026 | Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configur... |
| CVE-2026-36538 | HIGH | 7.3 | 0.3% | May 27, 2026 | Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow.sample. The password fo... |
| CVE-2026-36045 | HIGH | 7.3 | 1.3% | May 27, 2026 | picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The... |
| CVE-2026-36044 | HIGH | 8.8 | 1.9% | May 27, 2026 | @pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool(... |
| CVE-2026-35089 | HIGH | 8.7 | 0.6% | May 27, 2026 | In Slican telephone exchanges secure key is generated in a predictable manner using properties of the telephone exchange... |
| CVE-2026-1718 | HIGH | 7.5 | 0.4% | May 27, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted q... |
| CVE-2026-48906 | HIGH | 8.1 | 0.3% | May 27, 2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. |
| CVE-2026-45843 | HIGH | 8.2 | 0.3% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: slip: bound decode() reads against the compressed p... |
| CVE-2026-45839 | HIGH | 7.8 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: reject negative CO-RE accessor indices in bpf_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now