2026 CVE Vulnerabilities

67,706 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23261MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvme-fc: release admin tagset if init fails nvme_f...
CVE-2026-23260MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: regmap: maple: free entry on mas_store_gfp() failur...
CVE-2026-23259MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on ca...
CVE-2026-23258MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Initialize netdev pointer before que...
CVE-2026-23257MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic...
CVE-2026-23256MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setup_nic...
CVE-2026-23255MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype ...
CVE-2026-23254MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: gro: fix outer network offset The udp GRO com...
CVE-2026-23253HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: dvb-core: fix wrong reinitialization of ring...
CVE-2026-23252MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: get rid of the xchk_xfile_*_descr calls The x...
CVE-2026-23251MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a ...
CVE-2026-23250MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: check return value of xchk_scrub_create_subord...
CVE-2026-23249MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating tw...
CVE-2026-32610HIGH8.1Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server...
CVE-2026-30695MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access con...
CVE-2026-30345HIGH7.5A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitra...
CVE-2026-1463HIGH8.8The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu...
CVE-2026-3090HIGH7.2The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin...
CVE-2026-33004MEDIUM4.3Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, incre...
CVE-2026-33003MEDIUM4.3Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins co...
CVE-2026-33002HIGH7.5Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validatio...
CVE-2026-33001HIGH8.8Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar a...
CVE-2026-2992HIGH8.2The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due t...
CVE-2026-2991HIGH7.3The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in a...
CVE-2026-2559MEDIUM5.3The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now