2026 CVE Vulnerabilities
49,870 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46133 | HIGH | 7.5 | 0.6% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject unknown opcodes before ICRC proces... |
| CVE-2026-46130 | HIGH | 7.1 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split acros... |
| CVE-2026-46129 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info() error... |
| CVE-2026-46125 | HIGH | 8.8 | 0.3% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station if connection prep f... |
| CVE-2026-46124 | HIGH | 7.5 | 0.4% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file handle i... |
| CVE-2026-46123 | HIGH | 7.7 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: clamp rx length before skb_pu... |
| CVE-2026-46122 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: b43: enforce bounds check on firmware key ind... |
| CVE-2026-46121 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect memcg_path kfree() ... |
| CVE-2026-46120 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_gre: Use cached t->net in ip6erspan_changelink(... |
| CVE-2026-46117 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in man... |
| CVE-2026-46116 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm... |
| CVE-2026-46114 | HIGH | 7.5 | 0.5% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads ... |
| CVE-2026-46113 | HIGH | 8.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to u... |
| CVE-2026-46112 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix unlocked call to hns_roce_qp_remove()... |
| CVE-2026-46111 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix potential UAF in create_bi... |
| CVE-2026-46110 | HIGH | 7.5 | 0.5% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Prevent NULL deref when RX memory exha... |
| CVE-2026-46107 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm-thin: fix metadata refcount underflow There's a... |
| CVE-2026-46105 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Limit NVMe request size to 2 MiB Th... |
| CVE-2026-9804 | HIGH | 7.7 | 0.5% | May 28, 2026 | A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit... |
| CVE-2026-6226 | HIGH | 8.8 | 0.4% | May 28, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions ... |
| CVE-2026-9227 | HIGH | 8.8 | 0.7% | May 28, 2026 | The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and i... |
| CVE-2026-7862 | HIGH | 8.6 | 0.2% | May 28, 2026 | The Eupago Gateway For Woocommerce WordPress plugin before 4.7.2 does not properly restrict access to its refund request... |
| CVE-2026-7797 | HIGH | 7.5 | 0.6% | May 28, 2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to tim... |
| CVE-2026-7634 | HIGH | 7.2 | 0.4% | May 28, 2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in ... |
| CVE-2026-7052 | HIGH | 7.2 | 0.3% | May 28, 2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now