2026 CVE Vulnerabilities

64,840 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43084HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: make hash table per que...
CVE-2026-43083CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->t...
CVE-2026-43082MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: txgbe: leave space for null terminators on pro...
CVE-2026-43081MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix GENERIC_CMD register field masks for ...
CVE-2026-43080MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: l2tp: Drop large packets with UDP encap syzbot rep...
CVE-2026-43079MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Skip discovery table for off...
CVE-2026-43078HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in ...
CVE-2026-43077MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for ...
CVE-2026-43076HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate inline data i_size during inode rea...
CVE-2026-43075HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_write_end_i...
CVE-2026-43074HIGH7.8In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace...
CVE-2026-42509MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th...
CVE-2026-40010CRITICAL9.1Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a sessi...
CVE-2026-40001MEDIUM5.2There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which...
CVE-2026-35255MEDIUM6.6Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The ...
CVE-2026-1719HIGH7.5The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2...
CVE-2026-7841HIGH8.8A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user...
CVE-2026-7457MEDIUM6.4The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5....
CVE-2026-7448——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-7332HIGH7.2The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-6672MEDIUM6.4The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s...
CVE-2026-6344MEDIUM4.9The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i...
CVE-2026-35254MEDIUM6.1Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3...
CVE-2026-35253MEDIUM4.7Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected...
CVE-2026-23928MEDIUM6.8The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when H...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now