2026 CVE Vulnerabilities

48,948 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-64585HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing net...
CVE-2026-64584HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before ...
CVE-2026-64583HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake...
CVE-2026-5430CRITICAL10The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support...
CVE-2026-1728CRITICAL9.8Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level...
CVE-2026-19021HIGH7.3A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by thi...
CVE-2026-19020MEDIUM6.3A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2026-19019MEDIUM4.8A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_...
CVE-2026-19011MEDIUM5.5A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packa...
CVE-2026-19010HIGH7.3A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packag...
CVE-2026-19009HIGH7.3A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core...
CVE-2026-19008MEDIUM6.3A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape...
CVE-2026-18915MEDIUM5Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research...
CVE-2026-18649HIGH7.5A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements d...
CVE-2026-18597HIGH8.5The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re...
CVE-2026-0637MEDIUM4.4When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert...
CVE-2026-19007MEDIUM6.3A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedEle...
CVE-2026-19006MEDIUM6.3A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tool...
CVE-2026-19005MEDIUM6.3A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file s...
CVE-2026-18967HIGH8.1A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a...
CVE-2026-18510HIGH7.2The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-18400MEDIUM6.4The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Store...
CVE-2026-18395MEDIUM5.4The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o...
CVE-2026-18050HIGH7.5The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem...
CVE-2026-16954MEDIUM6.5The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now