2026 CVE Vulnerabilities

45,117 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-13163MEDIUM5.3Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai...
CVE-2026-13150MEDIUM6.9Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) ...
CVE-2026-52944MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a perm...
CVE-2026-11968MEDIUM5.5Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit
CVE-2026-52941MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid NULL deref of conn->lnk in smc_msg_e...
CVE-2026-52940MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tun: zero the whole vnet header in tun_put_user() ...
CVE-2026-52939MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler(...
CVE-2026-52938MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereference in bpf_sk_storage...
CVE-2026-52937MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tap: fix stack info leak in tap_ioctl() SIOCGIFHWAD...
CVE-2026-52936MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock ...
CVE-2026-52930MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch u...
CVE-2026-52928MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: af_unix: Reject SIOCATMARK on non-stream sockets S...
CVE-2026-52926MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: batman-adv: clear current gateway during teardown ...
CVE-2026-52925MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vrf: Fix a potential NPD when removing a port from ...
CVE-2026-52921MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: stop hash:* range iteration at en...
CVE-2026-52916MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: disallow unicast fragment in frag...
CVE-2026-52913MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: stop OGMv2 on disabled interface Wh...
CVE-2026-9724MEDIUM4.3The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1...
CVE-2026-9721MEDIUM4.3The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-9620MEDIUM6.4The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes i...
CVE-2026-9619MEDIUM4.3The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, an...
CVE-2026-9616MEDIUM4.3The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin...
CVE-2026-9612MEDIUM5.3The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure i...
CVE-2026-9184MEDIUM4.3The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2026-9183MEDIUM4.3The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now