2026 CVE Vulnerabilities

52,012 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-31454HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: save ailp before dropping the AIL lock in push...
CVE-2026-31453HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfs: avoid dereferencing log items after push callb...
CVE-2026-31452HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: convert inline data to extents when truncate ...
CVE-2026-31450HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_ino...
CVE-2026-31449HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ext4_ext_correct_ind...
CVE-2026-31447HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: reject mount if bigalloc with s_first_data_bl...
CVE-2026-31446HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in update_super_work when ...
CVE-2026-31442HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible invalid memory access...
CVE-2026-31435HIGH8.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under cer...
CVE-2026-0539HIGH8.5Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate th...
CVE-2026-6857HIGH7.5A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggre...
CVE-2026-6855HIGH7.1A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handl...
CVE-2026-6848HIGH8.1A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as ...
CVE-2026-33260HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-33258HIGH7.5By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressi...
CVE-2026-33257HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-33256HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-6846HIGH7.8A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Ext...
CVE-2026-4132HIGH7.2The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec...
CVE-2026-31433HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for...
CVE-2026-31432HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound req...
CVE-2026-31431HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla...
CVE-2026-6022HIGH7.5In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vuln...
CVE-2026-40542HIGH7.3Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-...
CVE-2026-22754HIGH7.5Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now