2026 CVE Vulnerabilities

51,446 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-2892HIGH7.5The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including...
CVE-2026-7402HIGH8.1Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This ...
CVE-2026-7399HIGH8.1Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege...
CVE-2026-41882HIGH7.5In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local f...
CVE-2026-31693HIGH7.8In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In se...
CVE-2026-31787HIGH7.8In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting pri...
CVE-2026-31786HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c Th...
CVE-2026-42512HIGH8.1As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. ...
CVE-2026-39457HIGH7.8When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whethe...
CVE-2026-35547HIGH8.1When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali...
CVE-2026-7164HIGH7.5Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a ...
CVE-2026-7270HIGH7.8An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data t...
CVE-2026-6520HIGH7.5OpenFlow v6 protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6519HIGH7.5MBIM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5657HIGH7.5iLBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5655HIGH7.5SDP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 allows denial of service
CVE-2026-5654HIGH7.5AMR-NB codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5653HIGH7.5DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-5402HIGH8.8TLS protocol dissector heap overflow in Wireshark 4.6.0 to 4.6.4 allows denial of service and possible code execution
CVE-2026-42511HIGH8.1The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitra...
CVE-2026-7379HIGH7.5Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-7378HIGH7.5Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-7376HIGH7.5Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-7375HIGH7.5UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
CVE-2026-6868HIGH7.5HTTP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now