2026 CVE Vulnerabilities

47,667 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-2891HIGH8.2The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP serve...
CVE-2026-13602HIGH7.7We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the ...
CVE-2026-5136HIGH8.8A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the call...
CVE-2026-53356HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset ...
CVE-2026-53354HIGH8.8In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm ...
CVE-2026-53341HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fhandle: fix UAF due to unlocked ->mnt_ns read in m...
CVE-2026-53330HIGH7.1In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix out-of-bounds read in dp_get_e...
CVE-2026-53329HIGH7In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector...
CVE-2026-5120HIGH8.1A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to ac...
CVE-2026-53906HIGH8.2MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload...
CVE-2026-53905HIGH7.1MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree...
CVE-2026-53904HIGH7.1MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each pass...
CVE-2026-53903HIGH8.1MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/tradin...
CVE-2026-14181HIGH7.5@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when...
CVE-2026-13323HIGH8.7In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h...
CVE-2026-13228HIGH8.8The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca...
CVE-2026-12142HIGH7.2The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2026-50043HIGH8.6Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-...
CVE-2026-12577HIGH8.7DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
CVE-2026-12576HIGH7.5DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.
CVE-2026-12575HIGH7.5DVP80ES3 with  Improper Resource Shutdown or Release vulnerability.
CVE-2026-12224HIGH8.8The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve...
CVE-2026-12158HIGH8.8The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2026-10538HIGH8.9Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowe...
CVE-2026-1239HIGH7.5The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now