2026 CVE Vulnerabilities

52,006 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4922HIGH8.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and...
CVE-2026-35368HIGH7.8A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves ...
CVE-2026-35352HIGH7A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility cre...
CVE-2026-35349HIGH7.7A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementat...
CVE-2026-35341HIGH7.1A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. Wh...
CVE-2026-35338HIGH7.3A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. Th...
CVE-2026-35548HIGH8.5An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix ...
CVE-2026-6861HIGH7.1A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially craf...
CVE-2026-6859HIGH8.8A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from...
CVE-2026-5750HIGH7.6An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated us...
CVE-2026-5749HIGH8.7Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain ...
CVE-2026-41651HIGH8.8PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, ...
CVE-2026-33610HIGH7.5A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondar...
CVE-2026-33602HIGH8.2A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, trig...
CVE-2026-33599HIGH8.1A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via eith...
CVE-2026-33597HIGH7.5PRSD detection denial of service
CVE-2026-33595HIGH7.5A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 conn...
CVE-2026-33594HIGH7.5A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH bac...
CVE-2026-33593HIGH7.5A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.
CVE-2026-33254HIGH7.5An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSd...
CVE-2026-31530HIGH7.8In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix use after free of parent_port in cxl_...
CVE-2026-31528HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf: Make sure to use pmu_ctx->pmu for groups Oli...
CVE-2026-31527HIGH7.8In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use generic driver_override ...
CVE-2026-31525HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Fix undefined behavior in interpreter sdiv/smo...
CVE-2026-31516HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm: prevent policy_hthresh.work from racing with ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now