2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45295MEDIUM6.5FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tr...
CVE-2026-44228MEDIUM5.4RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, conta...
CVE-2026-44227MEDIUM6.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contai...
CVE-2026-39878CRITICAL9.3Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration fo...
CVE-2026-34239HIGH7.5Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax...
CVE-2026-26483MEDIUM6.1Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template managemen...
CVE-2026-64207MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: dualpi2: fix GSO backlog accounting Whe...
CVE-2026-64206HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before tak...
CVE-2026-64205MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: i801: fix hardware state machine corruption in...
CVE-2026-64192MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if ...
CVE-2026-64191HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid ...
CVE-2026-64190MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: team: fix NULL pointer dereference in team_xmi...
CVE-2026-64189HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix race between dump and ip_set_...
CVE-2026-64188HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix endpoint use-after-free i...
CVE-2026-64187MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no ...
CVE-2026-58484HIGH7.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.listBackups()`...
CVE-2026-58482MEDIUM5.9Network-AI, a TypeScript/Node.js multi-agent orchestrator, has a shipped, exported, documented feature called `ApprovalI...
CVE-2026-58481MEDIUM6.5Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped fil...
CVE-2026-58414MEDIUM5.5Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recu...
CVE-2026-58413MEDIUM6.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, b...
CVE-2026-55645MEDIUM6.5xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of Client...
CVE-2026-55238MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Co...
CVE-2026-54538HIGH7.5xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to pr...
CVE-2026-54051CRITICAL9.9Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell comma...
CVE-2026-50743MEDIUM5.4A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now