2026 CVE Vulnerabilities

53,226 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22767HIGH7.3Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged att...
CVE-2026-24096HIGH8.8Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5...
CVE-2026-0932HIGH7.3Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in...
CVE-2026-23899HIGH8.8An improper access check allows unauthorized access to webservice endpoints.
CVE-2026-23898HIGH7.2Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
CVE-2026-21630HIGH8.8Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
CVE-2026-21629HIGH7.3The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was pote...
CVE-2026-5261HIGH7.3A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uplo...
CVE-2026-23411HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs acce...
CVE-2026-23410HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is...
CVE-2026-23408HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_...
CVE-2026-23407HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table...
CVE-2026-23406HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro...
CVE-2026-28265HIGH7.1PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access cou...
CVE-2026-27101HIGH7.2Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Impro...
CVE-2026-5258HIGH7.3A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/...
CVE-2026-4748HIGH7.5A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that...
CVE-2026-5292HIGH8.8Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ...
CVE-2026-5287HIGH8.8Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid...
CVE-2026-5286HIGH8.8Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via ...
CVE-2026-5285HIGH8.8Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-5284HIGH7.5Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render...
CVE-2026-5282HIGH8.1Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ...
CVE-2026-5281HIGH8.8Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render...
CVE-2026-5280HIGH8.8Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now