2026 CVE Vulnerabilities

67,198 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4274MEDIUM5.4Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-leve...
CVE-2026-24068HIGH8.8The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, wh...
CVE-2026-23398MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: icmp: fix NULL pointer dereference in icmp_tag_vali...
CVE-2026-23397HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths i...
CVE-2026-23396MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix NULL deref in mesh_matches_loca...
CVE-2026-4862HIGH8.8A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the functio...
CVE-2026-4263MEDIUM6.9Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u...
CVE-2026-4262MEDIUM6.9Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other u...
CVE-2026-4861HIGH8.8A weakness has been identified in Wavlink WL-NU516U1 260227. This vulnerability affects the function ftext of the file /...
CVE-2026-4860HIGH7.3A security flaw has been discovered in 648540858 wvp-GB28181-pro up to 2.7.4. This affects the function GenericFastJsonR...
CVE-2026-4874LOW3.1A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating t...
CVE-2026-4850CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. Affected is an unknown function of the f...
CVE-2026-4849MEDIUM6.1A vulnerability was identified in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file ...
CVE-2026-4848MEDIUM4.3A vulnerability was determined in dameng100 muucmf 1.9.5.20260309. This affects an unknown function of the file /admin/e...
CVE-2026-4847MEDIUM4.3A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /a...
CVE-2026-4747HIGH8.8Each RPCSEC_GSS data packet is validated by a routine which checks a signature in the packet. This routine copies a por...
CVE-2026-4652HIGH7.5On a system exposing an NVMe/TCP target, a remote client can trigger a kernel panic by sending a CONNECT command for an ...
CVE-2026-4247HIGH7.5When a challenge ACK is to be sent tcp_respond() constructs and sends the challenge ACK and consumes the mbuf that is pa...
CVE-2026-32680HIGH8.5The installer of RATOC RAID Monitoring Manager for Windows allows to customize the installation folder. If the installat...
CVE-2026-28760HIGH8.4The installer of RATOC RAID Monitoring Manager for Windows searches the current directory to load certain DLLs. If a use...
CVE-2026-1890MEDIUM5.3The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated u...
CVE-2026-1430MEDIUM4.8The WP Lightbox 2 WordPress plugin before 3.0.7 does not sanitise and escape some of its settings, which could allow hig...
CVE-2026-4846MEDIUM4.3A vulnerability has been found in dameng100 muucmf 1.9.5.20260309. The affected element is an unknown function of the fi...
CVE-2026-4845MEDIUM4.3A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is an unknown function of the file /admin/Member/inde...
CVE-2026-1206MEDIUM4.3The Elementor Website Builder plugin for WordPress is vulnerable to Incorrect Authorization to Sensitive Information Exp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now