2026 CVE Vulnerabilities

65,664 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-84884HIGH7.5IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent fo...
CVE-2026-80431MEDIUM6.8Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a ...
CVE-2026-80430MEDIUM4.6Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from ...
CVE-2026-100190MEDIUM6.3The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)...
CVE-2026-100187MEDIUM6.9The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as val...
CVE-2026-100177MEDIUM6.3The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a ...
CVE-2026-100176HIGH8.5The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported fro...
CVE-2026-100174MEDIUM5.1The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS)....
CVE-2026-100172HIGH8.5The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 t...
CVE-2026-100079——In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on tea...
CVE-2026-100078——In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to functi...
CVE-2026-100077——In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before retire hung submit Duri...
CVE-2026-100076——In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix xmit_frame/xmit_buf leaks o...
CVE-2026-100075CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters...
CVE-2026-100074——In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as unique BPF_REFCOUN...
CVE-2026-100073——In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow during writeback Co...
CVE-2026-100072——In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_get_primary_device() ...
CVE-2026-100071——In the Linux kernel, the following vulnerability has been resolved: net: hsr: free learned nodes on device setup failur...
CVE-2026-100070——In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrin...
CVE-2026-95832CRITICAL9.3Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code h...
CVE-2026-88421HIGH7.5Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthentica...
CVE-2026-88420MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through ...
CVE-2026-79153HIGH7.8Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driv...
CVE-2026-78902MEDIUM6.1Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via t...
CVE-2026-52622HIGH7.5An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 befo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now