2026 CVE Vulnerabilities

48,851 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-43096MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mshv: Fix infinite fault loop on permission-denied ...
CVE-2026-43095MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Fix errors in IRQ cleanup IRQs are ena...
CVE-2026-43094MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ixgbevf: add missing negotiate_features op to Hyper...
CVE-2026-43092MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xsk: validate MTU against usable frame size on bind...
CVE-2026-43090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfrm: fix refcount leak in xfrm_migrate_policy_find...
CVE-2026-43089MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_mapping() struct...
CVE-2026-43088MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: af_key: zero aligned sockaddr tail in PF_KEY e...
CVE-2026-43087MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Disable all pin interrupts durin...
CVE-2026-43086MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ipvs: fix NULL deref in ip_vs_add_service error pat...
CVE-2026-43085MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: initialize nfgenmsg in NL...
CVE-2026-43082MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: txgbe: leave space for null terminators on pro...
CVE-2026-43081MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix GENERIC_CMD register field masks for ...
CVE-2026-43080MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: l2tp: Drop large packets with UDP encap syzbot rep...
CVE-2026-43079MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Skip discovery table for off...
CVE-2026-43077MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for ...
CVE-2026-42509MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th...
CVE-2026-40001MEDIUM5.2There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which...
CVE-2026-35255MEDIUM6.6Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The ...
CVE-2026-7457MEDIUM6.4The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5....
CVE-2026-6672MEDIUM6.4The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s...
CVE-2026-6344MEDIUM4.9The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i...
CVE-2026-35254MEDIUM6.1Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3...
CVE-2026-35253MEDIUM4.7Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected...
CVE-2026-23927MEDIUM5.1A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead ...
CVE-2026-2306MEDIUM4.3The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation du...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now