2026 CVE Vulnerabilities

68,120 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23248HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in pe...
CVE-2026-23247MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tcp: secure_seq: add back ports to TS offset This ...
CVE-2026-23246HIGH8.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m...
CVE-2026-23245HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU o...
CVE-2026-23244HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_keys() ...
CVE-2026-23243HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_writ...
CVE-2026-23242HIGH7.5In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in...
CVE-2026-32565MEDIUM5.3Missing Authorization vulnerability in Ajay Contextual Related Posts contextual-related-posts allows Exploiting Incorrec...
CVE-2026-1217MEDIUM5.4The Yoast Duplicate Post plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2026-22730HIGH8.8A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metada...
CVE-2026-22729HIGH8.6A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass...
CVE-2026-22323HIGH7.1A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick ...
CVE-2026-22322HIGH7.1A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface allows an unauthentica...
CVE-2026-22321MEDIUM5.3A stack-based buffer overflow in the device's Telnet/SSH CLI login routine occurs when a unauthenticated attacker send a...
CVE-2026-22320MEDIUM6.5A stack-based buffer overflow in the CLI's TFTP file‑transfer command handling allows a low-privileged attacker with Tel...
CVE-2026-22319MEDIUM4.9A stack-based buffer overflow in the device's file installation workflow allows a high-privileged attacker to send overs...
CVE-2026-22318MEDIUM4.9A stack-based buffer overflow vulnerability in the device's file transfer parameter workflow allows a high-privileged at...
CVE-2026-22317HIGH7.2A command injection vulnerability in the device’s Root CA certificate transfer workflow allows a high-privileged attacke...
CVE-2026-22316MEDIUM6.5A remote attacker with user privileges for the webUI can use the setting of the TFTP Filename with a POST Request to tri...
CVE-2026-3512MEDIUM6.1The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'p' GET parameter...
CVE-2026-32608HIGH7Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to conf...
CVE-2026-32606HIGH7.6IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd...
CVE-2026-32596HIGH7.5Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authent...
CVE-2026-32268HIGH8.7The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the...
CVE-2026-4366MEDIUM5.8A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now