2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31550 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: bcm: bcm2835-power: Increase ASB control ... |
| CVE-2026-31549 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: cp2615: fix serial string NULL-deref at probe ... |
| CVE-2026-31547 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix missing runtime PM reference in ccs_mod... |
| CVE-2026-31546 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL deref in bond_debug_rlb_hash... |
| CVE-2026-31545 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFC: nxp-nci: allow GPIOs to sleep Allow the firmw... |
| CVE-2026-31544 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix NULL dereference on notify ... |
| CVE-2026-31543 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: crash_dump: don't log dm-crypt key bytes in read_ke... |
| CVE-2026-31542 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86/platform/uv: Handle deconfigured sockets When ... |
| CVE-2026-31540 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Check set_default_submission() before ... |
| CVE-2026-31537 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdirect_socket.send_io.b... |
| CVE-2026-31535 | MEDIUM | 4.7 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: make use of smbdirect_socket.recv_io.c... |
| CVE-2026-31052 | MEDIUM | 5.3 | 0.5% | Apr 24, 2026 | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout ... |
| CVE-2026-31050 | MEDIUM | 4.9 | 0.6% | Apr 24, 2026 | Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary... |
| CVE-2026-5265 | MEDIUM | 6.5 | 0.6% | Apr 24, 2026 | When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original... |
| CVE-2026-40690 | MEDIUM | 4.3 | 0.4% | Apr 24, 2026 | The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at le... |
| CVE-2026-38743 | MEDIUM | 4.3 | 0.4% | Apr 24, 2026 | The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and Task... |
| CVE-2026-41043 | MEDIUM | 6.5 | 0.6% | Apr 24, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache A... |
| CVE-2026-4078 | MEDIUM | 6.4 | 0.3% | Apr 24, 2026 | The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, i... |
| CVE-2026-3569 | MEDIUM | 5.3 | 0.4% | Apr 24, 2026 | The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1... |
| CVE-2026-3565 | MEDIUM | 4.3 | 0.2% | Apr 24, 2026 | The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3.... |
| CVE-2026-6810 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions... |
| CVE-2026-5428 | MEDIUM | 6.4 | 0.3% | Apr 24, 2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the I... |
| CVE-2026-5347 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. ... |
| CVE-2026-6393 | MEDIUM | 4.3 | 0.3% | Apr 24, 2026 | The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This ... |
| CVE-2026-5488 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now