2026 CVE Vulnerabilities
45,117 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13163 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai... |
| CVE-2026-13150 | MEDIUM | 6.9 | 0.3% | Jun 24, 2026 | Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) ... |
| CVE-2026-52944 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a perm... |
| CVE-2026-11968 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit |
| CVE-2026-52941 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid NULL deref of conn->lnk in smc_msg_e... |
| CVE-2026-52940 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: zero the whole vnet header in tun_put_user() ... |
| CVE-2026-52939 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler(... |
| CVE-2026-52938 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereference in bpf_sk_storage... |
| CVE-2026-52937 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tap: fix stack info leak in tap_ioctl() SIOCGIFHWAD... |
| CVE-2026-52936 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock ... |
| CVE-2026-52930 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch u... |
| CVE-2026-52928 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Reject SIOCATMARK on non-stream sockets S... |
| CVE-2026-52926 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: clear current gateway during teardown ... |
| CVE-2026-52925 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: vrf: Fix a potential NPD when removing a port from ... |
| CVE-2026-52921 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: stop hash:* range iteration at en... |
| CVE-2026-52916 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: disallow unicast fragment in frag... |
| CVE-2026-52913 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: stop OGMv2 on disabled interface Wh... |
| CVE-2026-9724 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1... |
| CVE-2026-9721 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2026-9620 | MEDIUM | 6.4 | 0.2% | Jun 24, 2026 | The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes i... |
| CVE-2026-9619 | MEDIUM | 4.3 | 0.3% | Jun 24, 2026 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, an... |
| CVE-2026-9616 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin... |
| CVE-2026-9612 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure i... |
| CVE-2026-9184 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2026-9183 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now