2026 CVE Vulnerabilities

51,104 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-43378HIGH7.8In the Linux kernel, the following vulnerability has been resolved: smb: server: fix use-after-free in smb2_open() The...
CVE-2026-43377HIGH8.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: Don't log keys in SMB3 signing and encryptio...
CVE-2026-43374HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: nexthop: fix percpu use-after-free in remove_n...
CVE-2026-43373HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net: ncsi: fix skb leak in error paths Early retur...
CVE-2026-43370HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix use-after-free race in VM acquire ...
CVE-2026-43368HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential overflow of shmem scatterli...
CVE-2026-43366HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: check if target buffer list is still...
CVE-2026-43365HIGH8.2In the Linux kernel, the following vulnerability has been resolved: xfs: fix undersized l_iclog_roundoff values If the...
CVE-2026-43362HIGH8.1In the Linux kernel, the following vulnerability has been resolved: smb: client: fix in-place encryption corruption in ...
CVE-2026-43353HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue Th...
CVE-2026-43352HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling...
CVE-2026-41588HIGH8.1RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth...
CVE-2026-41584HIGH7.5ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-chain version 6.0.2, Or...
CVE-2026-41576HIGH7.1Brave CMS is an open-source CMS. Prior to commit 6c56603, the contact form is publicly accessible (no authentication req...
CVE-2026-41570HIGH7.8PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child proce...
CVE-2026-41524HIGH8.7Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor ric...
CVE-2026-38361HIGH7.5Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-u...
CVE-2026-44340HIGH7.5PraisonAI is a multi-agent teams system. Prior to version 4.6.37, the _safe_extractall helper that all recipe pull, reci...
CVE-2026-44339HIGH8.6PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonai...
CVE-2026-44338HIGH7.3PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API...
CVE-2026-44334HIGH8.4PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools...
CVE-2026-44129HIGH8.3SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new G...
CVE-2026-44127HIGH8.8SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the iden...
CVE-2026-43350HIGH7.6In the Linux kernel, the following vulnerability has been resolved: smb: client: require a full NFS mode SID before rea...
CVE-2026-43347HIGH7.5In the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: monaco: Reserve full Gunyah metad...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now