2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-65710HIGH7.1sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the P...
CVE-2026-65709HIGH8.7sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allo...
CVE-2026-65708HIGH8.6sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated ...
CVE-2026-65707HIGH8.5Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract ar...
CVE-2026-65623HIGH8.7Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via C...
CVE-2026-66027HIGH8.7Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated at...
CVE-2026-65693HIGH8.6Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administ...
CVE-2026-64255HIGH8.8In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() ...
CVE-2026-64251HIGH7.8In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_...
CVE-2026-64247HIGH8.4In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Bound the bank index when queryi...
CVE-2026-64243HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: simple-mux: Fix enum control bounds c...
CVE-2026-64237HIGH7.1In the Linux kernel, the following vulnerability has been resolved: Input: elan_i2c - validate firmware size before use...
CVE-2026-64235HIGH8.1In the Linux kernel, the following vulnerability has been resolved: x86/ftrace: Relocate %rip-relative percpu refs in d...
CVE-2026-64226HIGH7.8In the Linux kernel, the following vulnerability has been resolved: sched_ext: Avoid UAF in scx_root_enable_workfn() in...
CVE-2026-64225HIGH7.8In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: CGX: add bounds check to cgx_speed_mb...
CVE-2026-64224HIGH7.8In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix double free in rvu_rep_rsrc_init(...
CVE-2026-64223HIGH8.1In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: consume only present negotiated TTL...
CVE-2026-64222HIGH7In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on A...
CVE-2026-64221HIGH7.8In the Linux kernel, the following vulnerability has been resolved: spi: ti-qspi: fix use-after-free after DMA setup fa...
CVE-2026-64219HIGH7In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_i...
CVE-2026-64218HIGH7.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_g...
CVE-2026-64217HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter...
CVE-2026-64210HIGH7.5In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix unlocked writing to ICOSQ Duri...
CVE-2026-64209HIGH7.1In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: Fix out-of-bounds array access...
CVE-2026-64208HIGH7.5In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-ver...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now