2026 CVE Vulnerabilities

55,130 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-64210HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ Duri...
CVE-2026-64209HIGH7.1In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access...
CVE-2026-64208HIGH7.5In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-ver...
CVE-2026-17039LOW3.1A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based autho...
CVE-2026-8789HIGH8.1The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2026-8308MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa...
CVE-2026-7007MEDIUM4.6The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl....
CVE-2026-66007MEDIUM6.5Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builder...
CVE-2026-66006MEDIUM6.9lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs...
CVE-2026-66005MEDIUM6.3Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that ...
CVE-2026-66004MEDIUM6BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that all...
CVE-2026-58630CRITICAL9.8Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58586CRITICAL9.8Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the sys...
CVE-2026-57106CRITICAL10Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-56163CRITICAL10Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el...
CVE-2026-55732HIGH8.7Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-R...
CVE-2026-55731MEDIUM6.6Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI...
CVE-2026-55730HIGH8.7Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenti...
CVE-2026-55729HIGH7.7Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all pla...
CVE-2026-55728LOW3.8Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L...
CVE-2026-49326MEDIUM6.5Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest...
CVE-2026-17059MEDIUM6.5A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloa...
CVE-2026-16802MEDIUM6.5Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and ear...
CVE-2026-16801HIGH8.8Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2...
CVE-2026-16800HIGH8.8Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 20...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now