2026 CVE Vulnerabilities

68,730 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23260MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: regmap: maple: free entry on mas_store_gfp() failur...
CVE-2026-23259MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/rw: free potentially allocated iovec on ca...
CVE-2026-23258MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Initialize netdev pointer before que...
CVE-2026-23257MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in PF setup_nic...
CVE-2026-23256MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: liquidio: Fix off-by-one error in VF setup_nic...
CVE-2026-23255MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: add proper RCU protection to /proc/net/ptype ...
CVE-2026-23254MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: gro: fix outer network offset The udp GRO com...
CVE-2026-23253HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: dvb-core: fix wrong reinitialization of ring...
CVE-2026-23252MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: get rid of the xchk_xfile_*_descr calls The x...
CVE-2026-23251MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: only call xf{array,blob}_destroy if we have a ...
CVE-2026-23250MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: check return value of xchk_scrub_create_subord...
CVE-2026-23249MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfs: check for deleted cursors when revalidating tw...
CVE-2026-32610HIGH8.1Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server...
CVE-2026-30695MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in the web-based configuration interface of Zucchetti Axess access con...
CVE-2026-30345HIGH7.5A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitra...
CVE-2026-1463HIGH8.8The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu...
CVE-2026-3090HIGH7.2The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin...
CVE-2026-33004MEDIUM4.3Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, incre...
CVE-2026-33003MEDIUM4.3Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins co...
CVE-2026-33002HIGH7.5Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validatio...
CVE-2026-33001HIGH8.8Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar a...
CVE-2026-2992HIGH8.2The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due t...
CVE-2026-2991HIGH7.3The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in a...
CVE-2026-2559MEDIUM5.3The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2026-2512MEDIUM6.4The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all ver...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now