2026 CVE Vulnerabilities

53,362 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45813HIGH8.8Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper valida...
CVE-2026-45812MEDIUM6.5Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event....
CVE-2026-45811HIGH7.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr...
CVE-2026-16743MEDIUM5.5A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root ...
CVE-2026-16730MEDIUM5.5A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer set...
CVE-2026-15810HIGH8.7A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6...
CVE-2026-15243HIGH7.4Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th...
CVE-2026-10610HIGH8.5Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.
CVE-2026-7483HIGH8.5Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a...
CVE-2026-16634CRITICAL9.8TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is ...
CVE-2026-15663MEDIUM4.9The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injecti...
CVE-2026-15401HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf...
CVE-2026-10033HIGH7.3The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,...
CVE-2026-63317MEDIUM5.6Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected:...
CVE-2026-56392LOW1.8GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation...
CVE-2026-56391MEDIUM4.6GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch...
CVE-2026-49745HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49744HIGH7.8Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a writ...
CVE-2026-49743HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of...
CVE-2026-24727CRITICAL9.3An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporat...
CVE-2026-15821MEDIUM6.4The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-15739MEDIUM6.4The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' ...
CVE-2026-15704CRITICAL9.8In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authori...
CVE-2026-15346MEDIUM6.1The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '...
CVE-2026-12702MEDIUM4.9In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now