2026 CVE Vulnerabilities
52,012 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31454 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: save ailp before dropping the AIL lock in push... |
| CVE-2026-31453 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: avoid dereferencing log items after push callb... |
| CVE-2026-31452 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: convert inline data to extents when truncate ... |
| CVE-2026-31450 | HIGH | 8.8 | 0.5% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: publish jinode after initialization ext4_ino... |
| CVE-2026-31449 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: validate p_idx bounds in ext4_ext_correct_ind... |
| CVE-2026-31447 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: reject mount if bigalloc with s_first_data_bl... |
| CVE-2026-31446 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix use-after-free in update_super_work when ... |
| CVE-2026-31442 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible invalid memory access... |
| CVE-2026-31435 | HIGH | 8.8 | 0.3% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under cer... |
| CVE-2026-0539 | HIGH | 8.5 | 0.1% | Apr 22, 2026 | Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate th... |
| CVE-2026-6857 | HIGH | 7.5 | 0.7% | Apr 22, 2026 | A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggre... |
| CVE-2026-6855 | HIGH | 7.1 | 0.2% | Apr 22, 2026 | A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handl... |
| CVE-2026-6848 | HIGH | 8.1 | 0.3% | Apr 22, 2026 | A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as ... |
| CVE-2026-33260 | HIGH | 7.5 | 0.5% | Apr 22, 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni... |
| CVE-2026-33258 | HIGH | 7.5 | 0.6% | Apr 22, 2026 | By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressi... |
| CVE-2026-33257 | HIGH | 7.5 | 0.5% | Apr 22, 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni... |
| CVE-2026-33256 | HIGH | 7.5 | 0.6% | Apr 22, 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni... |
| CVE-2026-6846 | HIGH | 7.8 | 0.2% | Apr 22, 2026 | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Ext... |
| CVE-2026-4132 | HIGH | 7.2 | 1.0% | Apr 22, 2026 | The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec... |
| CVE-2026-31433 | HIGH | 8.8 | 0.6% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for... |
| CVE-2026-31432 | HIGH | 8.8 | 0.5% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound req... |
| CVE-2026-31431 | HIGH | 7.8 | 94.5% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla... |
| CVE-2026-6022 | HIGH | 7.5 | 0.3% | Apr 22, 2026 | In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vuln... |
| CVE-2026-40542 | HIGH | 7.3 | 0.5% | Apr 22, 2026 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-... |
| CVE-2026-22754 | HIGH | 7.5 | 0.3% | Apr 22, 2026 | Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now