2026 CVE Vulnerabilities

51,945 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-31678HIGH7.8In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release...
CVE-2026-31676HIGH7.5In the Linux kernel, the following vulnerability has been resolved: rxrpc: only handle RESPONSE during service challeng...
CVE-2026-31675HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in p...
CVE-2026-31674HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rt: reject oversized addrnr in rt_m...
CVE-2026-31673HIGH7.8In the Linux kernel, the following vulnerability has been resolved: af_unix: read UNIX_DIAG_VFS data under unix_state_l...
CVE-2026-42171HIGH7.8NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as ...
CVE-2026-41503HIGH7.5BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea...
CVE-2026-41502HIGH7.5BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of...
CVE-2026-41477HIGH7.8Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and ex...
CVE-2026-41476HIGH8.8Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's c...
CVE-2026-41433HIGH8.4OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to befo...
CVE-2026-41429HIGH8.8arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr...
CVE-2026-41907HIGH7.5uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buf...
CVE-2026-41894HIGH7.1SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a d...
CVE-2026-41421HIGH8.8SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messa...
CVE-2026-41419HIGH7.64ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an ...
CVE-2026-41416HIGH7.5PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer ...
CVE-2026-41414HIGH7.4Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.ym...
CVE-2026-41326HIGH8.2Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-33666HIGH7.5Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18....
CVE-2026-33662HIGH7.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-33524HIGH7.5Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18....
CVE-2026-42039HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively wal...
CVE-2026-42038HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostna...
CVE-2026-42035HIGH7.4Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadg...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now