2026 CVE Vulnerabilities
51,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31576 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: hackrf: fix to not free memory after the dev... |
| CVE-2026-31570 | HIGH | 8.8 | 0.3% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: can: gw: fix OOB heap access in cgw_csum_crc8_rel()... |
| CVE-2026-31569 | HIGH | 7.3 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Handle the case that EIOINTC's core... |
| CVE-2026-31568 | HIGH | 7.1 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add missing secure storage access fixups f... |
| CVE-2026-31566 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix fence put before wait in amdgpu_amd... |
| CVE-2026-31563 | HIGH | 7.5 | 0.5% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: macb: Use dev_consume_skb_any() to free TX SKB... |
| CVE-2026-31558 | HIGH | 8.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Make kvm_get_vcpu_by_cpuid() more r... |
| CVE-2026-31557 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet: move async event work off nvmet-wq For targ... |
| CVE-2026-31554 | HIGH | 7.8 | 0.2% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: futex: Require sys_futex_requeue() to have identica... |
| CVE-2026-31553 | HIGH | 8.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix the descriptor address in __kvm_at_... |
| CVE-2026-31552 | HIGH | 7.5 | 0.5% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Return -ENOMEM instead of -EAGAIN if ... |
| CVE-2026-31548 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pms... |
| CVE-2026-31541 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix trace_marker copy link list updates W... |
| CVE-2026-31539 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: introduce smbdirect_socket.recv_io.... |
| CVE-2026-31538 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdirect_socket.recv_io.c... |
| CVE-2026-5367 | HIGH | 8.6 | 0.9% | Apr 24, 2026 | A flaw was found in OVN (Open Virtual Network). A remote attacker, by sending crafted DHCPv6 (Dynamic Host Configuration... |
| CVE-2026-6043 | HIGH | 8.8 | 0.5% | Apr 24, 2026 | P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted network... |
| CVE-2026-23902 | HIGH | 8.1 | 0.4% | Apr 24, 2026 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permission... |
| CVE-2026-41044 | HIGH | 8.8 | 1.0% | Apr 24, 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, A... |
| CVE-2026-40466 | HIGH | 8.8 | 4.8% | Apr 24, 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br... |
| CVE-2026-6272 | HIGH | 8.5 | 0.3% | Apr 24, 2026 | A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v... |
| CVE-2026-21728 | HIGH | 7.5 | 0.6% | Apr 24, 2026 | Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, dep... |
| CVE-2026-1952 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability. |
| CVE-2026-5364 | HIGH | 8.1 | 1.1% | Apr 24, 2026 | The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions... |
| CVE-2026-6947 | HIGH | 8.7 | 0.5% | Apr 24, 2026 | DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now