2026 CVE Vulnerabilities

48,877 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-5766MEDIUM6.3An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-...
CVE-2026-43073MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86-64: rename misleadingly named '__copy_user_noca...
CVE-2026-43072MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/vc4: platform_get_irq_byname() returns an int ...
CVE-2026-43069MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ll: Fix firmware leak on error path ...
CVE-2026-43068MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocate block from corrupted group in ...
CVE-2026-43066MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: fix iloc.bh leak in ext4_fc_replay_inode() er...
CVE-2026-43065MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: always drain queued discard work in ext4_mb_r...
CVE-2026-43064MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix not releasing workqueue on .re...
CVE-2026-43061MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix TX deadlock when using DMA `dmae...
CVE-2026-39103MEDIUM5.5Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to caus...
CVE-2026-35192MEDIUM6.5An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session ...
CVE-2026-34956MEDIUM5.9A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the users...
CVE-2026-7778MEDIUM5An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has b...
CVE-2026-30246MEDIUM6.5Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the...
CVE-2026-28510MEDIUM5.9eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably pr...
CVE-2026-27694MEDIUM5.4Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the ema...
CVE-2026-27693MEDIUM5.4Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML...
CVE-2026-27644MEDIUM6.5Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality write...
CVE-2026-6262MEDIUM6.5The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is...
CVE-2026-43574MEDIUM6.5OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolve...
CVE-2026-43572MEDIUM6.3OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO in...
CVE-2026-43570MEDIUM6.5OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository p...
CVE-2026-43868MEDIUM5.3Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0....
CVE-2026-3601MEDIUM4.3The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss...
CVE-2026-7824MEDIUM5.9An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is en...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now