2026 CVE Vulnerabilities
51,198 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43133 | HIGH | 7.9 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emula... |
| CVE-2026-43128 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix double dma_buf_unpin in failure path... |
| CVE-2026-43126 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: mixer: oss: Add card disconnect checkpoints ... |
| CVE-2026-43646 | HIGH | 7.5 | 0.4% | May 6, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Wicket. This issue affects Apache Wi... |
| CVE-2026-43120 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix double free related to rereg_user_m... |
| CVE-2026-43116 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master ... |
| CVE-2026-43113 | HIGH | 8.8 | 0.2% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: wl1251: validate packet IDs before indexing t... |
| CVE-2026-43112 | HIGH | 8.8 | 0.4% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/smb/client: fix out-of-bounds read in cifs_sanit... |
| CVE-2026-43111 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: roccat: fix use-after-free in roccat_report_ev... |
| CVE-2026-43110 | HIGH | 8.8 | 0.2% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: validate bsscfg indices in IF event... |
| CVE-2026-43106 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix incorrect dentry refcount in cachef... |
| CVE-2026-43101 | HIGH | 7.5 | 0.4% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix potential NULL dereferences in __io... |
| CVE-2026-43099 | HIGH | 7.5 | 0.5% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: fix null-ptr-deref in icmp_build_probe(... |
| CVE-2026-43097 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI: hv: Fix double ida_free in hv_pci_probe error ... |
| CVE-2026-43093 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xsk: tighten UMEM headroom validation to account fo... |
| CVE-2026-43091 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Wait for RCU readers during policy netns exit... |
| CVE-2026-43084 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: make hash table per que... |
| CVE-2026-43078 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in ... |
| CVE-2026-43076 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate inline data i_size during inode rea... |
| CVE-2026-43075 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix out-of-bounds write in ocfs2_write_end_i... |
| CVE-2026-43074 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace... |
| CVE-2026-1719 | HIGH | 7.5 | 0.3% | May 6, 2026 | The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2... |
| CVE-2026-7841 | HIGH | 8.8 | 0.6% | May 6, 2026 | A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user... |
| CVE-2026-7332 | HIGH | 7.2 | 0.4% | May 6, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-23928 | HIGH | 7.3 | 0.3% | May 6, 2026 | The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when H... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now