2026 CVE Vulnerabilities

70,289 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29069MEDIUM5.3Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() end...
CVE-2026-28784HIGH7.2Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload usi...
CVE-2026-28783CRITICAL9.1Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to...
CVE-2026-28782MEDIUM4.3Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does n...
CVE-2026-28781MEDIUM6.5Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows f...
CVE-2026-28697CRITICAL9.1Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can ...
CVE-2026-28696HIGH7.5Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, i...
CVE-2026-28695HIGH7.2Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Temp...
CVE-2026-23812MEDIUM4.2A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless clie...
CVE-2026-23811LOW3.1A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restriction...
CVE-2026-23810LOW3.1A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-...
CVE-2026-23809HIGH7.6A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs....
CVE-2026-23808HIGH8.1A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to i...
CVE-2026-23601MEDIUM5.4A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can ge...
CVE-2026-22760MEDIUM5.5Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Condi...
CVE-2026-20005MEDIUM5.8Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthentica...
CVE-2026-26673HIGH7.5An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a de...
CVE-2026-26514HIGH7.5An Argument Injection vulnerability exists in bird-lg-go before commit 6187a4e. The traceroute module uses shlex.Split t...
CVE-2026-26478CRITICAL9.8A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attac...
CVE-2026-22285MEDIUM4.4Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A h...
CVE-2026-23238MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: romfs: check sb_set_blocksize() return value romfs...
CVE-2026-23237MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: platform/x86: classmate-laptop: Add missing NULL po...
CVE-2026-23236MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fbdev: smscufx: properly copy ioctl memory to kerne...
CVE-2026-23235HIGH7.1In the Linux kernel, the following vulnerability has been resolved: f2fs: fix out-of-bounds access in sysfs attribute r...
CVE-2026-23234HIGH7.8In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid UAF in f2fs_write_end_io() As s...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now