2026 CVE Vulnerabilities

60,172 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56232HIGH8.8Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited...
CVE-2026-56231HIGH7.6Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId ...
CVE-2026-56223CRITICAL9.3Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that all...
CVE-2026-13163MEDIUM5.3Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai...
CVE-2026-13140LOW1.1Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exp...
CVE-2026-12242HIGH8.8The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and includin...
CVE-2026-13150MEDIUM6.9Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) ...
CVE-2026-52944MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a perm...
CVE-2026-52943HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb...
CVE-2026-11968MEDIUM5.5Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit
CVE-2026-10745HIGH7.9Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows...
CVE-2026-7761HIGH8.8The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all ver...
CVE-2026-56052HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel B...
CVE-2026-52942HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set befo...
CVE-2026-52941MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid NULL deref of conn->lnk in smc_msg_e...
CVE-2026-52940MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tun: zero the whole vnet header in tun_put_user() ...
CVE-2026-52939MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler(...
CVE-2026-52938MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereference in bpf_sk_storage...
CVE-2026-52937MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tap: fix stack info leak in tap_ioctl() SIOCGIFHWAD...
CVE-2026-52936MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock ...
CVE-2026-52935HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial...
CVE-2026-52934HIGH8.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets ba...
CVE-2026-52933HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get...
CVE-2026-52932HIGH7.5In the Linux kernel, the following vulnerability has been resolved: xfrm: ipcomp: Free destination pages on acomp error...
CVE-2026-52931CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender va...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now