2026 CVE Vulnerabilities
43,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66339 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t... |
| CVE-2026-66338 | MEDIUM | 5.4 | 0.2% | Jul 24, 2026 | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes tha... |
| CVE-2026-66337 | MEDIUM | 6.5 | 0.2% | Jul 24, 2026 | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes ... |
| CVE-2026-55985 | MEDIUM | 5.3 | 0.1% | Jul 24, 2026 | The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o... |
| CVE-2026-66038 | MEDIUM | 6.5 | 0.3% | Jul 24, 2026 | FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video de... |
| CVE-2026-66037 | MEDIUM | 5.5 | 0.3% | Jul 24, 2026 | FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d... |
| CVE-2026-57531 | MEDIUM | 5.4 | 0.2% | Jul 24, 2026 | Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo... |
| CVE-2026-57530 | MEDIUM | 5.4 | 0.2% | Jul 24, 2026 | Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk... |
| CVE-2026-48037 | MEDIUM | 6.3 | 0.3% | Jul 24, 2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P... |
| CVE-2026-64254 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER... |
| CVE-2026-64253 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() P... |
| CVE-2026-64252 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Prevent initial console buffer from land... |
| CVE-2026-64250 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Report dying CPU to RCU in stop_this_cpu... |
| CVE-2026-64236 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: davinci: fix division by zero on missing clock... |
| CVE-2026-64234 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tty: serial: pch_uart: add check for dma_alloc_cohe... |
| CVE-2026-64233 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: hold opts->lock across XU walks i... |
| CVE-2026-64231 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: don't dump registers past the mapped r... |
| CVE-2026-64230 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: regulator: tps65219: fix irq_data.rdev not being as... |
| CVE-2026-64220 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in f... |
| CVE-2026-64215 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send... |
| CVE-2026-64214 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: powerpc/time: Remove redundant preempt_disable|enab... |
| CVE-2026-64213 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Add lock protection to lm90_alert Sa... |
| CVE-2026-64212 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer bef... |
| CVE-2026-64211 | MEDIUM | 5.5 | 0.2% | Jul 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-onlin... |
| CVE-2026-8308 | MEDIUM | 6.1 | — | Jul 24, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now