2026 CVE Vulnerabilities

50,970 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18755HIGH7.3A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search di...
CVE-2026-18754CRITICAL9.1The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio...
CVE-2026-18753CRITICAL9.1The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS terminatio...
CVE-2026-64565In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix heap-buffer-overflow in ims_pc...
CVE-2026-64564CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-...
CVE-2026-64563HIGH7.8In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart r...
CVE-2026-64562HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR fr...
CVE-2026-64561HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* m...
CVE-2026-16623HIGH8The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a g...
CVE-2026-16618CRITICAL9.8The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file conten...
CVE-2026-16548MEDIUM6.5The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be...
CVE-2026-16547MEDIUM5.9The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log en...
CVE-2026-16546MEDIUM4.3The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJA...
CVE-2026-16536MEDIUM5.3The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef...
CVE-2026-16296MEDIUM4.7The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect...
CVE-2026-16295MEDIUM4.3The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch p...
CVE-2026-16293MEDIUM6.8The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Po...
CVE-2026-16070LOW2.7The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before upd...
CVE-2026-16069MEDIUM6.8The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted t...
CVE-2026-16068LOW3.5The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does...
CVE-2026-16056MEDIUM4.3The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler...
CVE-2026-16035MEDIUM4.3The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP ...
CVE-2026-15958CRITICAL9.3The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its ...
CVE-2026-15233MEDIUM4.8The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at...
CVE-2026-14939MEDIUM6.8The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetchi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now