2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-31456MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk: fix race between concurrent split and ...
CVE-2026-31451MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: replace BUG_ON with proper error handling in ...
CVE-2026-31445MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: avoid use of half-online-committed c...
CVE-2026-31443MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix crash when the event log is di...
CVE-2026-31441MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix memory leak when a wq is reset...
CVE-2026-31440MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix leaking event log memory Duri...
CVE-2026-31439MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx: xdma: Fix regmap init error hand...
CVE-2026-31438MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfs: Fix kernel BUG in netfs_limit_iter() for ITE...
CVE-2026-31437MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfs: Fix NULL pointer dereference in netfs_unbuff...
CVE-2026-31434MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: fix leak of kobject name for sub-group space...
CVE-2026-31192MEDIUM6.5Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attacker...
CVE-2026-33601MEDIUM4.9If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a ...
CVE-2026-33600MEDIUM4.9An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistenc...
CVE-2026-33262MEDIUM5.9An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leadin...
CVE-2026-33261MEDIUM5.9A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.
CVE-2026-33259MEDIUM5Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the...
CVE-2026-1930MEDIUM4.3The Emailchef plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2026-1913MEDIUM6.4The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login_li...
CVE-2026-1395MEDIUM6.4The Gutentools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Slider block's block_id at...
CVE-2026-6845MEDIUM5A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to c...
CVE-2026-6844MEDIUM5.5A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service ...
CVE-2026-6843MEDIUM5.5A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By cr...
CVE-2026-6396MEDIUM4.3The Fast & Fancy Filter – 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and incl...
CVE-2026-6294MEDIUM4.3The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and inclu...
CVE-2026-6246MEDIUM6.4The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_r...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now