2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-71211HIGH7.1MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr...
CVE-2026-71209HIGH7.5audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes agai...
CVE-2026-71206HIGH8.3Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded...
CVE-2026-71202HIGH7.5The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only cl...
CVE-2026-70378HIGH7.5imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is posit...
CVE-2026-70377HIGH7.5imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * rat...
CVE-2026-6639HIGH7.5The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2026-6627HIGH8.2The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a...
CVE-2026-6147HIGH8.8The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2026-6079HIGH7.3The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing...
CVE-2026-6020HIGH7.2The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action ...
CVE-2026-64581HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_pol...
CVE-2026-64580HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netde...
CVE-2026-64578HIGH8.2In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before readin...
CVE-2026-64577HIGH7.5In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_ech...
CVE-2026-64576HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate...
CVE-2026-64575HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc ...
CVE-2026-64574HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update e...
CVE-2026-64570HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on a...
CVE-2026-64568HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double f...
CVE-2026-64567HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries th...
CVE-2026-61485HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue af...
CVE-2026-61483HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: al...
CVE-2026-59675HIGH7.5When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a siz...
CVE-2026-55997HIGH8.8Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These token...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now