2026 CVE Vulnerabilities

44,809 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-63739HIGH8.3SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows da...
CVE-2026-63737HIGH7.1SurrealDB versions before 3.1.5 contain a denial of service vulnerability where authenticated users can crash the server...
CVE-2026-63735HIGH8.6SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticat...
CVE-2026-16247HIGH7.3In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this proces...
CVE-2026-16246HIGH7.3In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows g...
CVE-2026-14448HIGH8.6An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi...
CVE-2026-13577HIGH8.2Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan...
CVE-2026-9833HIGH7.1The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape...
CVE-2026-6656HIGH7.5Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the bu...
CVE-2026-13142HIGH8.1The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a wo...
CVE-2026-12970HIGH7.1The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attri...
CVE-2026-12592HIGH7.5The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu...
CVE-2026-11349HIGH8.6The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0...
CVE-2026-10081HIGH8.8The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe...
CVE-2026-42566HIGH7.5Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User...
CVE-2026-12484HIGH7.8A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d...
CVE-2026-64186HIGH7.1In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Remove latent out-of-bounds access in IO...
CVE-2026-64181HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm: fix __vm_normal_page() to handle missing suppor...
CVE-2026-64178HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_ad...
CVE-2026-64176HIGH8.1In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix driver-set TX rates on old ...
CVE-2026-64175HIGH7.5In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: stop TX during firmware restart...
CVE-2026-64172HIGH7.1In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Disable AVIC IPI virtualization on Hygon ...
CVE-2026-64158HIGH7.3In the Linux kernel, the following vulnerability has been resolved: netfs: Fix write streaming disablement if fd open O...
CVE-2026-64153HIGH8.8In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return value check...
CVE-2026-64152HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommu: Handle unmap error when iommu_debug is enabl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now