2026 CVE Vulnerabilities

52,054 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-31435HIGH8.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under cer...
CVE-2026-0539HIGH8.5Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate th...
CVE-2026-6857HIGH7.5A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggre...
CVE-2026-6855HIGH7.1A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handl...
CVE-2026-6848HIGH8.1A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as ...
CVE-2026-33260HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-33258HIGH7.5By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressi...
CVE-2026-33257HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-33256HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-6846HIGH7.8A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Ext...
CVE-2026-4132HIGH7.2The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec...
CVE-2026-31433HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for...
CVE-2026-31432HIGH8.8In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound req...
CVE-2026-31431HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla...
CVE-2026-6022HIGH7.5In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vuln...
CVE-2026-40542HIGH7.3Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-...
CVE-2026-22754HIGH7.5Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=...
CVE-2026-22753HIGH7.5Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMat...
CVE-2026-22747HIGH8.1Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509...
CVE-2026-6834HIGH7.1The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arb...
CVE-2026-6833HIGH7.1The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbi...
CVE-2026-5398HIGH8.4The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal ...
CVE-2026-41458HIGH8.2OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows u...
CVE-2026-41146HIGH8.7facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_jso...
CVE-2026-41145HIGH8.2MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now