2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63886 | CRITICAL | 9.8 | 0.7% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before ... |
| CVE-2026-63857 | CRITICAL | 9.8 | 0.3% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment add... |
| CVE-2026-63830 | CRITICAL | 9.4 | 0.4% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms ... |
| CVE-2026-63825 | CRITICAL | 9.8 | 0.4% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent ... |
| CVE-2026-63808 | CRITICAL | 9.8 | 0.5% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_d... |
| CVE-2026-63800 | CRITICAL | 9.8 | 0.5% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() W... |
| CVE-2026-63795 | CRITICAL | 10 | 0.5% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error ... |
| CVE-2026-53399 | CRITICAL | 9.8 | 0.5% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4... |
| CVE-2026-53398 | CRITICAL | 9.8 | 0.5% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfs... |
| CVE-2026-53384 | CRITICAL | 9.8 | 0.5% | Jul 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifi... |
| CVE-2026-9323 | CRITICAL | 9.2 | 0.4% | Jul 18, 2026 | The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by c... |
| CVE-2026-16117 | CRITICAL | 10 | 0.3% | Jul 18, 2026 | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segme... |
| CVE-2026-16158 | CRITICAL | 10 | 0.2% | Jul 18, 2026 | Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by conca... |
| CVE-2026-15631 | CRITICAL | 10 | 0.3% | Jul 18, 2026 | Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket desti... |
| CVE-2026-47865 | CRITICAL | 9.8 | 0.7% | Jul 18, 2026 | VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be ab... |
| CVE-2026-55518 | CRITICAL | 9.6 | 0.3% | Jul 17, 2026 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association a... |
| CVE-2026-54159 | CRITICAL | 10 | 0.8% | Jul 17, 2026 | PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsear... |
| CVE-2026-52348 | CRITICAL | 9.8 | 0.3% | Jul 17, 2026 | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. |
| CVE-2026-48062 | CRITICAL | 9.8 | 0.4% | Jul 17, 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/St... |
| CVE-2026-13446 | CRITICAL | 9.8 | 0.2% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it... |
| CVE-2026-8859 | CRITICAL | 9.9 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations ... |
| CVE-2026-8635 | CRITICAL | 9.9 | 0.3% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul... |
| CVE-2026-8505 | CRITICAL | 9.8 | 0.6% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthentica... |
| CVE-2026-8481 | CRITICAL | 9.9 | 0.4% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API ... |
| CVE-2026-8476 | CRITICAL | 9.9 | 0.5% | Jul 17, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now