2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31435HIGH8.8In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under cer...
CVE-2026-31434MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix leak of kobject name for sub-group space...
CVE-2026-31192MEDIUM6.5Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attacker...
CVE-2026-0539HIGH8.5Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate th...
CVE-2026-6857HIGH7.5A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggre...
CVE-2026-6855HIGH7.1A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handl...
CVE-2026-6848HIGH8.1A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as ...
CVE-2026-33601MEDIUM4.9If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a ...
CVE-2026-33600MEDIUM4.9An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistenc...
CVE-2026-33262MEDIUM5.9An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leadin...
CVE-2026-33261MEDIUM5.9A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
CVE-2026-33260HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-33259MEDIUM5Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the...
CVE-2026-33258HIGH7.5By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressi...
CVE-2026-33257HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-33256HIGH7.5An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni...
CVE-2026-1930MEDIUM4.3The Emailchef plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2026-1913MEDIUM6.4The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login_li...
CVE-2026-1395MEDIUM6.4The Gutentools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Slider block's block_id at...
CVE-2026-6846HIGH7.8A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Ext...
CVE-2026-6845MEDIUM5A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to c...
CVE-2026-6844MEDIUM5.5A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service ...
CVE-2026-6843MEDIUM5.5A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By cr...
CVE-2026-6396MEDIUM4.3The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and incl...
CVE-2026-6294MEDIUM4.3The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and inclu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now