2026 CVE Vulnerabilities

48,280 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-56245HIGH8.8Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time ...
CVE-2026-56244HIGH7.1Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient ro...
CVE-2026-56232HIGH8.8Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited...
CVE-2026-56231HIGH7.6Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId ...
CVE-2026-12242HIGH8.8The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and includin...
CVE-2026-52943HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb...
CVE-2026-10745HIGH7.9Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows...
CVE-2026-7761HIGH8.8The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all ver...
CVE-2026-56052HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel B...
CVE-2026-52942HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set befo...
CVE-2026-52935HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial...
CVE-2026-52934HIGH8.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets ba...
CVE-2026-52933HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get...
CVE-2026-52932HIGH7.5In the Linux kernel, the following vulnerability has been resolved: xfrm: ipcomp: Free destination pages on acomp error...
CVE-2026-52929HIGH7.5In the Linux kernel, the following vulnerability has been resolved: sctp: stream: fully roll back denied add-stream sta...
CVE-2026-52927HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: fix OOB read in compat_mtw_fro...
CVE-2026-52923HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range...
CVE-2026-52922HIGH7.5In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation error b...
CVE-2026-52920HIGH8.3In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound polic...
CVE-2026-52919HIGH7.8In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during s...
CVE-2026-52918HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll(...
CVE-2026-52917HIGH7.1In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one p...
CVE-2026-52915HIGH7.1In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists ...
CVE-2026-52912HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while que...
CVE-2026-9710HIGH7.7The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now