2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2026-14857The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his...
CVE-2026-13613The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using ...
CVE-2026-13612The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al...
CVE-2026-13177The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user...
CVE-2026-13171The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han...
CVE-2026-13168The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users...
CVE-2026-12976The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a...
CVE-2026-68450In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root in...
CVE-2026-68449In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: fix infinite loop in NCQ tag c...
CVE-2026-68448In the Linux kernel, the following vulnerability has been resolved: ovl: check access to copy_file_range source with sr...
CVE-2026-68447In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint ...
CVE-2026-68446In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_si...
CVE-2026-68445In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming w...
CVE-2026-68444In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix NULL dereference in ffa_part...
CVE-2026-68443In the Linux kernel, the following vulnerability has been resolved: hwmon: (gigabyte_waterforce) Stop device IO before ...
CVE-2026-68442In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split...
CVE-2026-68441In the Linux kernel, the following vulnerability has been resolved: net/sched: Handle TC_ACT_REDIRECT from qdisc filter...
CVE-2026-68440In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix heap overflow when reading module E...
CVE-2026-68439In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: fix possible NULL-pointer deref...
CVE-2026-68438In the Linux kernel, the following vulnerability has been resolved: smp: Make CSD lock acquisition atomic for debug mod...
CVE-2026-68437In the Linux kernel, the following vulnerability has been resolved: drm/imagination: Fit paired fragment job in the cor...
CVE-2026-68436In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: use kvzalloc to allocate struct dc...
CVE-2026-68435In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix address space mismatch in kexec comm...
CVE-2026-68434In the Linux kernel, the following vulnerability has been resolved: serial: 8250_mid: Fix NULL function pointer derefer...
CVE-2026-68433In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front le...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now