2026 CVE Vulnerabilities

50,911 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6972MEDIUM6.4The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of th...
CVE-2026-6639HIGH7.5The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2026-6627HIGH8.2The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a...
CVE-2026-6147HIGH8.8The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2026-6079HIGH7.3The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing...
CVE-2026-6020HIGH7.2The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action ...
CVE-2026-64581HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_pol...
CVE-2026-64580HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netde...
CVE-2026-64579In the Linux kernel, the following vulnerability has been resolved: xfrm: policy: preallocate inexact bins before xfrm_...
CVE-2026-64578HIGH8.2In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before readin...
CVE-2026-64577HIGH7.5In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_ech...
CVE-2026-64576HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate...
CVE-2026-64575HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc ...
CVE-2026-64574HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update e...
CVE-2026-64573In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NVM tag length underflow in TLV...
CVE-2026-64572In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: free fib_alias with kfree_rcu() on inser...
CVE-2026-64571In the Linux kernel, the following vulnerability has been resolved: wifi: p54: validate RX frame length in p54_rx_eepro...
CVE-2026-64570HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on a...
CVE-2026-64569In the Linux kernel, the following vulnerability has been resolved: mpls: fix NULL deref in mpls_valid_fib_dump_req() o...
CVE-2026-64568HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double f...
CVE-2026-64567HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries th...
CVE-2026-64566CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_s...
CVE-2026-61486CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Luc...
CVE-2026-61485HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af...
CVE-2026-61484CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now