2026 CVE Vulnerabilities

66,304 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-97524HIGH7.5In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Onc...
CVE-2026-97523HIGH7.5In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state chang...
CVE-2026-97522——In the Linux kernel, the following vulnerability has been resolved: mptcp: fix bad accounting in __mptcp_subflow_push_p...
CVE-2026-97228LOW2.7Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status com...
CVE-2026-27867MEDIUM4.8An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio...
CVE-2026-97898HIGH8.4Insecure Direct Object Reference / missing object-level authorization in the Akia keyless entry cloud service. The unloc...
CVE-2026-92106LOW2.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_htm...
CVE-2026-97863MEDIUM6.3The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to ...
CVE-2026-92573MEDIUM6.5Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message d...
CVE-2026-92564HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-92560HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-92550HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-88848MEDIUM4.2The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is c...
CVE-2026-86837MEDIUM5.3The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored deta...
CVE-2026-80514MEDIUM5.3The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address heade...
CVE-2026-6088MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6087MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6086MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6085MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6084MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6083MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-6082MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ...
CVE-2026-96752HIGH7.2The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys...
CVE-2026-96568HIGH7.2The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_n...
CVE-2026-96448MEDIUM6.6A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now