2026 CVE Vulnerabilities

66,372 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23421MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/configfs: Free ctx_restore_mid_bb in release...
CVE-2026-23420MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: wlcore: Fix a locking bug Make sure that wl-...
CVE-2026-23419MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/rds: Fix circular locking dependency in rds_tcp...
CVE-2026-23418MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe/reg_sr: Fix leak on xa_store failure Free t...
CVE-2026-27655MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on M...
CVE-2026-5467MEDIUM6.1A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component...
CVE-2026-4108MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Perm...
CVE-2026-4107MEDIUM5.4Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count a...
CVE-2026-3880MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client P...
CVE-2026-3879MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Deta...
CVE-2026-28703MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Betwee...
CVE-2026-28756MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on D...
CVE-2026-28754MEDIUM4.8Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists rep...
CVE-2026-5462LOW3.3A vulnerability was identified in Wahoo Fitness SYSTM App up to 7.2.1 on Android. Impacted is an unknown function of the...
CVE-2026-4350HIGH8.1The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, ...
CVE-2026-5458LOW3.3A weakness has been identified in Noelse Individuals & Pro App up to 2.1.7 on Android. This impacts an unknown function ...
CVE-2026-5457LOW3.3A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on Android. This affects an unk...
CVE-2026-5456LOW3.3A vulnerability was identified in Align Technology My Invisalign App 3.12.4 on Android. The impacted element is an unkno...
CVE-2026-5455LOW3.3A vulnerability was determined in Dialogue App up to 4.3.2 on Android. The affected element is an unknown function of th...
CVE-2026-5463CRITICAL9.8Command injection vulnerability in console.run_module_with_output() in pymetasploit3 through version 1.0.6 allows attack...
CVE-2026-5454LOW3.3A vulnerability was found in GRID Organiser App up to 1.0.5 on Android. Impacted is an unknown function of the file file...
CVE-2026-5453LOW3.3A vulnerability has been found in Rico só vantagem pra investir App up to 4.58.32.12421 on Android. This issue affects s...
CVE-2026-35549MEDIUM6.5An issue was discovered in MariaDB Server before 11.4.10, 11.5.x through 11.8.x before 11.8.6, and 12.x before 12.2.2. I...
CVE-2026-35545HIGH8.2An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed...
CVE-2026-35544MEDIUM5.3An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitiz...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now