2026 CVE Vulnerabilities

60,172 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-52930MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch u...
CVE-2026-52929HIGH7.5In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream sta...
CVE-2026-52928MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: af_unix: Reject SIOCATMARK on non-stream sockets S...
CVE-2026-52927HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_fro...
CVE-2026-52926MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: batman-adv: clear current gateway during teardown ...
CVE-2026-52925MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vrf: Fix a potential NPD when removing a port from ...
CVE-2026-52924CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling ...
CVE-2026-52923HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range...
CVE-2026-52922HIGH7.5In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation error b...
CVE-2026-52921MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: stop hash:* range iteration at en...
CVE-2026-52920HIGH8.3In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound polic...
CVE-2026-52919HIGH7.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during s...
CVE-2026-52918HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll(...
CVE-2026-52917HIGH7.1In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one p...
CVE-2026-52916MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: disallow unicast fragment in frag...
CVE-2026-52915HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists ...
CVE-2026-52914CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounti...
CVE-2026-52913MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: stop OGMv2 on disabled interface Wh...
CVE-2026-52912HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while que...
CVE-2026-9724MEDIUM4.3The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1...
CVE-2026-9721MEDIUM4.3The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-9710HIGH7.7The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handl...
CVE-2026-9709HIGH7.7The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing...
CVE-2026-9643HIGH7.2The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI se...
CVE-2026-9620MEDIUM6.4The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now