2026 CVE Vulnerabilities

56,095 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53910LOW2.1diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in ...
CVE-2026-52863MEDIUM5.9In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together...
CVE-2026-50252CRITICAL9.3In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret...
CVE-2026-50251MEDIUM5.3In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value g...
CVE-2026-50248MEDIUM6.5In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that res...
CVE-2026-50243LOW3.7In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of ...
CVE-2026-50046MEDIUM5.9In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queri...
CVE-2026-50045MEDIUM5.3In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-s...
CVE-2026-46582LOW3.7In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be ...
CVE-2026-44690HIGH7.5In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with ...
CVE-2026-44687LOW3.7In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate l...
CVE-2026-44621MEDIUM5.9With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-...
CVE-2026-42955LOW3.7In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost do...
CVE-2026-41637LOW3.7In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted...
CVE-2026-40691HIGH7.5In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the r...
CVE-2026-32665HIGH7.5In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two b...
CVE-2026-16560MEDIUM5.3A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the s...
CVE-2026-16232CRITICAL9.8An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote at...
CVE-2026-14932MEDIUM6.5In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vuln...
CVE-2026-14865MEDIUM5.3In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML wi...
CVE-2026-14586MEDIUM5.9In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under ...
CVE-2026-13192MEDIUM6.5In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PD...
CVE-2026-13190HIGH8.1In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities all...
CVE-2026-13189HIGH7.5In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell c...
CVE-2026-13188MEDIUM5.9In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potential...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now