2026 CVE Vulnerabilities

43,564 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-63742MEDIUM5.3SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths...
CVE-2026-63741MEDIUM6.9SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS ...
CVE-2026-63738MEDIUM5.3SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g...
CVE-2026-63736MEDIUM5.1SurrealDB before 3.2.0 contains a server-side request forgery vulnerability in the JWKS fetcher that validates only the ...
CVE-2026-63734MEDIUM6.9SurrealDB versions before 3.2.0 contain a denial of service vulnerability in the SurrealML header parser that allows aut...
CVE-2026-63733MEDIUM6.5SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS...
CVE-2026-16254MEDIUM4.3A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o...
CVE-2026-15813MEDIUM6.5A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The int...
CVE-2026-15588MEDIUM5.3A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` a...
CVE-2026-2445MEDIUM6.1The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encod...
CVE-2026-8825MEDIUM4.9The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning p...
CVE-2026-13432MEDIUM5.4The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing a...
CVE-2026-13156MEDIUM5.4The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it veri...
CVE-2026-12973MEDIUM6.5The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i...
CVE-2026-12972MEDIUM5.3The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i...
CVE-2026-12898MEDIUM6.5The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value be...
CVE-2026-12724MEDIUM4.3The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re...
CVE-2026-12723MEDIUM5.3The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u...
CVE-2026-11868MEDIUM5.3The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio...
CVE-2026-10724MEDIUM4.8The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review...
CVE-2026-45138MEDIUM5.4CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` v...
CVE-2026-64185MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sysfs: don't remove existing directory on update fa...
CVE-2026-64184MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: call missing mem_cgroup_ite...
CVE-2026-64183MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: efi: Allocate runtime workqueue before ACPI init S...
CVE-2026-64182MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: fix memory block reference lea...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now