2026 CVE Vulnerabilities
51,071 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20113 | MEDIUM | 5.3 | 0.3% | Mar 25, 2026 | A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software... |
| CVE-2026-20112 | MEDIUM | 4.8 | 0.2% | Mar 25, 2026 | A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software... |
| CVE-2026-20110 | MEDIUM | 6.5 | 0.1% | Mar 25, 2026 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of se... |
| CVE-2026-20108 | MEDIUM | 5.4 | 0.2% | Mar 25, 2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem... |
| CVE-2026-20104 | MEDIUM | 6.1 | 0.2% | Mar 25, 2026 | A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS93... |
| CVE-2026-20083 | MEDIUM | 6.5 | 0.1% | Mar 25, 2026 | A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, ... |
| CVE-2026-1917 | MEDIUM | 4.3 | 0.2% | Mar 25, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Login Disable allows Functionality Bypa... |
| CVE-2026-33268 | MEDIUM | 6.9 | 0.3% | Mar 25, 2026 | Nanoleaf Lines 12.3.2 does not authenticate firmware file uploads. A remote, unauthenticated attacker can upload firmwar... |
| CVE-2026-23514 | MEDIUM | 6.5 | 1.0% | Mar 25, 2026 | Kiteworks is a private data network (PDN). Versions 9.2.0 and 9.2.1 of Kiteworks Core have an access control vulnerabili... |
| CVE-2026-4816 | MEDIUM | 5.4 | 0.1% | Mar 25, 2026 | A Reflected Cross Site Scripting (XSS) vulnerability has been found in Support Board v3.7.7. This vulnerability allows a... |
| CVE-2026-3591 | MEDIUM | 5.4 | 0.4% | Mar 25, 2026 | A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a spec... |
| CVE-2026-3119 | MEDIUM | 6.5 | 0.6% | Mar 25, 2026 | Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affec... |
| CVE-2026-23394 | MEDIUM | 4.7 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Give up GC if MSG_PEEK intervened. Igor U... |
| CVE-2026-23389 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory leak in ice_set_ringparam() In ice... |
| CVE-2026-23386 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: gve: fix incorrect buffer cleanup in gve_tx_clean_p... |
| CVE-2026-23385 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: clone set on flush only Syzb... |
| CVE-2026-23384 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Fix kernel stack leak in ionic_create_c... |
| CVE-2026-23382 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: Add HID_CLAIMED_INPUT guards in raw_event call... |
| CVE-2026-23381 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix nd_tbl NULL dereference when IPv6 ... |
| CVE-2026-23380 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix WARN_ON in tracing_buffers_mmap_close ... |
| CVE-2026-23379 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: ets: fix divide by zero in the offload p... |
| CVE-2026-23377 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ice: change XDP RxQ frag_size from DMA write length... |
| CVE-2026-23376 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-fcloop: Check remoteport port_state before ca... |
| CVE-2026-23375 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm: thp: deny THP for files on anonymous inodes fi... |
| CVE-2026-23374 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: blktrace: fix __this_cpu_read/write in preemptible ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now