2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-63886CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before ...
CVE-2026-63857CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment add...
CVE-2026-63830CRITICAL9.4In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms ...
CVE-2026-63825CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent ...
CVE-2026-63808CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: exfat: fix potential use-after-free in exfat_find_d...
CVE-2026-63800CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: pNFS: Fix use-after-free in pnfs_update_layout() W...
CVE-2026-63795CRITICAL10In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error ...
CVE-2026-53399CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: release layout stid on setlease failure nfs4...
CVE-2026-53398CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfs...
CVE-2026-53384CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: serial: 8250_dw: unregister 8250 port if clk_notifi...
CVE-2026-9323CRITICAL9.2The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by c...
CVE-2026-16117CRITICAL10Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segme...
CVE-2026-16158CRITICAL10Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by conca...
CVE-2026-15631CRITICAL10Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket desti...
CVE-2026-47865CRITICAL9.8VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be ab...
CVE-2026-55518CRITICAL9.6Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association a...
CVE-2026-54159CRITICAL10PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsear...
CVE-2026-52348CRITICAL9.8cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
CVE-2026-48062CRITICAL9.8CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/St...
CVE-2026-13446CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it...
CVE-2026-8859CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations ...
CVE-2026-8635CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul...
CVE-2026-8505CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthentica...
CVE-2026-8481CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API ...
CVE-2026-8476CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now