2026 CVE Vulnerabilities

51,177 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34474HIGH7.5Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to ...
CVE-2026-34473HIGH7.5Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H...
CVE-2026-33079HIGH7.5In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `...
CVE-2026-29090HIGH8.8### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and ...
CVE-2026-42503HIGH8.8gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen...
CVE-2026-29080HIGH8.8A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbit...
CVE-2026-23870HIGH7.5A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo...
CVE-2026-21661HIGH8.4An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Co...
CVE-2026-20185HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG...
CVE-2026-20167HIGH7.7A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, ...
CVE-2026-20035HIGH7.2A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to con...
CVE-2026-20034HIGH8.8A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att...
CVE-2026-6788HIGH7.8Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.
CVE-2026-6787HIGH7.8Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Pr...
CVE-2026-6691HIGH8.6The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling ...
CVE-2026-41288HIGH7.8Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allo...
CVE-2026-40562HIGH7.5Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Gazelle incorrectl...
CVE-2026-6210HIGH8.7A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. Wh...
CVE-2026-43283HIGH8.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ec_bhf: Fix dma_free_coherent() dma ...
CVE-2026-43281HIGH7.1In the Linux kernel, the following vulnerability has been resolved: mailbox: Prevent out-of-bounds access in fw_mbox_in...
CVE-2026-43280HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/xe: Add bounds check on pat_index to prevent OO...
CVE-2026-43279HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at...
CVE-2026-43278HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dm: clear cloned request bio pointer when last clon...
CVE-2026-43276HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix double destroy_workqueue on service ...
CVE-2026-43274HIGH8.4In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: fix out-of-bounds access in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now