2026 CVE Vulnerabilities

43,297 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-66339MEDIUM6.5A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches t...
CVE-2026-66338MEDIUM5.4A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes tha...
CVE-2026-66337MEDIUM6.5A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes ...
CVE-2026-55985MEDIUM5.3The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o...
CVE-2026-66038MEDIUM6.5FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video de...
CVE-2026-66037MEDIUM5.5FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF d...
CVE-2026-57531MEDIUM5.4Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo...
CVE-2026-57530MEDIUM5.4Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk...
CVE-2026-48037MEDIUM6.3Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-64254MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER...
CVE-2026-64253MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() P...
CVE-2026-64252MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: MIPS: DEC: Prevent initial console buffer from land...
CVE-2026-64250MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: LoongArch: Report dying CPU to RCU in stop_this_cpu...
CVE-2026-64236MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: davinci: fix division by zero on missing clock...
CVE-2026-64234MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tty: serial: pch_uart: add check for dma_alloc_cohe...
CVE-2026-64233MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: hold opts->lock across XU walks i...
CVE-2026-64231MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: don't dump registers past the mapped r...
CVE-2026-64230MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: regulator: tps65219: fix irq_data.rdev not being as...
CVE-2026-64220MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in f...
CVE-2026-64215MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send...
CVE-2026-64214MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: powerpc/time: Remove redundant preempt_disable|enab...
CVE-2026-64213MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Add lock protection to lm90_alert Sa...
CVE-2026-64212MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: don't dereference a pointer bef...
CVE-2026-64211MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: srcu: Don't queue workqueue handlers to never-onlin...
CVE-2026-8308MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Softwa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now