2026 CVE Vulnerabilities

48,614 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46327HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The func...
CVE-2026-46326HIGH8.4In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct...
CVE-2026-11788HIGH7.5A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us...
CVE-2026-46324HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink ...
CVE-2026-46323HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive()...
CVE-2026-46322HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one(...
CVE-2026-46321HIGH7.1In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_...
CVE-2026-46320HIGH7.4In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp()...
CVE-2026-46319HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after...
CVE-2026-46317HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_l...
CVE-2026-2638HIGH7.3A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a loc...
CVE-2026-49742HIGH7.1Backend users with file download permissions were able to download files from the fallback storage of the file abstracti...
CVE-2026-49741HIGH8.7Backend users with write access to the form_definition database table were able to directly create, update, or delete fo...
CVE-2026-47346HIGH7.6Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F...
CVE-2026-47343HIGH7.2Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on fold...
CVE-2026-11607HIGH7.6Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, whi...
CVE-2026-46748HIGH7.8A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a bina...
CVE-2026-46746HIGH8.8A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly s...
CVE-2026-24349HIGH8.2A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Run...
CVE-2026-8365HIGH8.8The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_...
CVE-2026-11616HIGH8.8The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and in...
CVE-2026-5068HIGH8.8A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD...
CVE-2026-11572HIGH8.8Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to impro...
CVE-2026-9662HIGH8.1The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and in...
CVE-2026-9185HIGH7.5The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now