2026 CVE Vulnerabilities
48,851 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43096 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: mshv: Fix infinite fault loop on permission-denied ... |
| CVE-2026-43095 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Fix errors in IRQ cleanup IRQs are ena... |
| CVE-2026-43094 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ixgbevf: add missing negotiate_features op to Hyper... |
| CVE-2026-43092 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: validate MTU against usable frame size on bind... |
| CVE-2026-43090 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: fix refcount leak in xfrm_migrate_policy_find... |
| CVE-2026-43089 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_mapping() struct... |
| CVE-2026-43088 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: af_key: zero aligned sockaddr tail in PF_KEY e... |
| CVE-2026-43087 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Disable all pin interrupts durin... |
| CVE-2026-43086 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipvs: fix NULL deref in ip_vs_add_service error pat... |
| CVE-2026-43085 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: initialize nfgenmsg in NL... |
| CVE-2026-43082 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: txgbe: leave space for null terminators on pro... |
| CVE-2026-43081 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix GENERIC_CMD register field masks for ... |
| CVE-2026-43080 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: l2tp: Drop large packets with UDP encap syzbot rep... |
| CVE-2026-43079 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Skip discovery table for off... |
| CVE-2026-43077 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for ... |
| CVE-2026-42509 | MEDIUM | 6.1 | 0.4% | May 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th... |
| CVE-2026-40001 | MEDIUM | 5.2 | 0.1% | May 6, 2026 | There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which... |
| CVE-2026-35255 | MEDIUM | 6.6 | 0.2% | May 6, 2026 | Vulnerability in the Oracle Cloud Native Environment Command Line Interface product of Oracle Open Source Projects. The ... |
| CVE-2026-7457 | MEDIUM | 6.4 | 0.3% | May 6, 2026 | The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.... |
| CVE-2026-6672 | MEDIUM | 6.4 | 0.2% | May 6, 2026 | The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s... |
| CVE-2026-6344 | MEDIUM | 4.9 | 0.6% | May 6, 2026 | The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i... |
| CVE-2026-35254 | MEDIUM | 6.1 | 0.1% | May 6, 2026 | Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3... |
| CVE-2026-35253 | MEDIUM | 4.7 | 0.1% | May 6, 2026 | Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected... |
| CVE-2026-23927 | MEDIUM | 5.1 | 0.2% | May 6, 2026 | A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead ... |
| CVE-2026-2306 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation du... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now