2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-31550MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: pmdomain: bcm: bcm2835-power: Increase ASB control ...
CVE-2026-31549MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: i2c: cp2615: fix serial string NULL-deref at probe ...
CVE-2026-31547MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix missing runtime PM reference in ccs_mod...
CVE-2026-31546MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix NULL deref in bond_debug_rlb_hash...
CVE-2026-31545MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: NFC: nxp-nci: allow GPIOs to sleep Allow the firmw...
CVE-2026-31544MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix NULL dereference on notify ...
CVE-2026-31543MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crash_dump: don't log dm-crypt key bytes in read_ke...
CVE-2026-31542MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/platform/uv: Handle deconfigured sockets When ...
CVE-2026-31540MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: Check set_default_submission() before ...
CVE-2026-31537MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: smb: server: make use of smbdirect_socket.send_io.b...
CVE-2026-31535MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: smb: client: make use of smbdirect_socket.recv_io.c...
CVE-2026-31052MEDIUM5.3An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Checkout ...
CVE-2026-31050MEDIUM4.9Cross Site Scripting vulnerability in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary...
CVE-2026-5265MEDIUM6.5When generating an ICMP Destination Unreachable or Packet Too Big response, the handler copies a portion of the original...
CVE-2026-40690MEDIUM4.3The asset dependency graph did not restrict nodes by the viewer's DAG read permissions: a user with read access to at le...
CVE-2026-38743MEDIUM4.3The authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and Task...
CVE-2026-41043MEDIUM6.5Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache A...
CVE-2026-4078MEDIUM6.4The ITERAS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes (iteras-ordering, i...
CVE-2026-3569MEDIUM5.3The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1...
CVE-2026-3565MEDIUM4.3The Taqnix plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3....
CVE-2026-6810MEDIUM5.3The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions...
CVE-2026-5428MEDIUM6.4The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the I...
CVE-2026-5347MEDIUM5.3The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. ...
CVE-2026-6393MEDIUM4.3The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This ...
CVE-2026-5488MEDIUM5.3The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now