2026 CVE Vulnerabilities

43,286 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-56786CRITICAL9.8RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp lengt...
CVE-2026-54917CRITICAL10SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the ...
CVE-2026-54089CRITICAL9.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-54088CRITICAL9.3File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-50549CRITICAL9.8Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by...
CVE-2026-50548CRITICAL9.8Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by...
CVE-2026-6094CRITICAL9.1Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically ...
CVE-2026-56123CRITICAL9.8socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5...
CVE-2026-55413CRITICAL9.4ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-54030CRITICAL9.3LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem...
CVE-2026-54849CRITICAL9.3Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
CVE-2026-54843CRITICAL9.3Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
CVE-2026-54836CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows ...
CVE-2026-54823CRITICAL9.9Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
CVE-2026-41120CRITICAL9.8Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust...
CVE-2026-53260CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk...
CVE-2026-53247CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in m...
CVE-2026-53246CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COO...
CVE-2026-53228CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offlo...
CVE-2026-53225CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup(...
CVE-2026-53224CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list...
CVE-2026-53221CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_...
CVE-2026-53216CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer ...
CVE-2026-53215CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use...
CVE-2026-53186CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now