2026 CVE Vulnerabilities

53,531 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-26740HIGH8.2Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToE...
CVE-2026-23270HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: Only allow act_ct to bind to clsact/ingr...
CVE-2026-23269HIGH7.1In the Linux kernel, the following vulnerability has been resolved: apparmor: validate DFA start states are in bounds i...
CVE-2026-23268HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privil...
CVE-2026-23262HIGH7.8In the Linux kernel, the following vulnerability has been resolved: gve: Fix stats report corruption on queue count cha...
CVE-2026-23253HIGH7.8In the Linux kernel, the following vulnerability has been resolved: media: dvb-core: fix wrong reinitialization of ring...
CVE-2026-32610HIGH8.1Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.2, the Glances REST API web server...
CVE-2026-30345HIGH7.5A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitra...
CVE-2026-1463HIGH8.8The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Local File Inclu...
CVE-2026-3090HIGH7.2The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin...
CVE-2026-33002HIGH7.5Jenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validatio...
CVE-2026-33001HIGH8.8Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar a...
CVE-2026-2992HIGH8.2The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due t...
CVE-2026-2991HIGH7.3The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in a...
CVE-2026-24063HIGH8.2When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a ...
CVE-2026-24062HIGH7.8The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signatu...
CVE-2026-32609HIGH7.5Glances is an open-source system cross-platform monitoring tool. The GHSA-gh4x fix (commit 5d3de60) addressed unauthenti...
CVE-2026-32693HIGH8.8In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which ...
CVE-2026-23248HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf/core: Fix refcount bug and potential UAF in pe...
CVE-2026-23246HIGH8.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: bounds-check link_id in ieee80211_m...
CVE-2026-23245HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: act_gate: snapshot parameters with RCU o...
CVE-2026-23244HIGH7.1In the Linux kernel, the following vulnerability has been resolved: nvme: fix memory allocation in nvme_pr_read_keys() ...
CVE-2026-23243HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/umad: Reject negative data_len in ib_umad_writ...
CVE-2026-23242HIGH7.5In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix potential NULL pointer dereference in...
CVE-2026-22730HIGH8.8A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metada...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now