2026 CVE Vulnerabilities
51,446 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-2892 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including... |
| CVE-2026-7402 | HIGH | 8.1 | 0.4% | Apr 30, 2026 | Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This ... |
| CVE-2026-7399 | HIGH | 8.1 | 0.3% | Apr 30, 2026 | Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege... |
| CVE-2026-41882 | HIGH | 7.5 | 0.4% | Apr 30, 2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local f... |
| CVE-2026-31693 | HIGH | 7.8 | 0.1% | Apr 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In se... |
| CVE-2026-31787 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting pri... |
| CVE-2026-31786 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c Th... |
| CVE-2026-42512 | HIGH | 8.1 | 1.4% | Apr 30, 2026 | As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. ... |
| CVE-2026-39457 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whethe... |
| CVE-2026-35547 | HIGH | 8.1 | 0.3% | Apr 30, 2026 | When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali... |
| CVE-2026-7164 | HIGH | 7.5 | 0.4% | Apr 30, 2026 | Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a ... |
| CVE-2026-7270 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data t... |
| CVE-2026-6520 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6519 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-5657 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-5655 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service |
| CVE-2026-5654 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-5653 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-5402 | HIGH | 8.8 | 0.4% | Apr 30, 2026 | TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution |
| CVE-2026-42511 | HIGH | 8.1 | 0.4% | Apr 30, 2026 | The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitra... |
| CVE-2026-7379 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-7378 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-7376 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-7375 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6868 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now