2026 CVE Vulnerabilities

53,398 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-23022MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leak in idpf_vc_core_deinit() Mak...
CVE-2026-23021MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: usb: pegasus: fix memory leak in update_eth_re...
CVE-2026-23020MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: 3com: 3c59x: fix possible null dereference in ...
CVE-2026-23019MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix NULL dereference on dev...
CVE-2026-23018MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: release path before initializing extent tree...
CVE-2026-23017MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: idpf: fix error handling in the init_task on load ...
CVE-2026-23016MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: inet: frags: drop fraglist conntrack references Ja...
CVE-2026-23015MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: gpio: mpsse: fix reference leak in gpio_mpsse_probe...
CVE-2026-1251MEDIUM5.4The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Objec...
CVE-2026-0683MEDIUM6.5The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the...
CVE-2026-1431MEDIUM5.3The Booking Calendar plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check...
CVE-2026-25156MEDIUM6.3HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all ...
CVE-2026-25154MEDIUM6.1LocalSend is a free, open-source app that allows users to share files and messages with nearby devices over their local ...
CVE-2026-25152MEDIUM6.5Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node....
CVE-2026-23835MEDIUM5.7LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Ba...
CVE-2026-1700MEDIUM5.4A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknow...
CVE-2026-1690MEDIUM4.7A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /b...
CVE-2026-25050MEDIUM5.3Vendure is an open-source headless commerce platform. Prior to version 3.5.3, the `NativeAuthenticationStrategy.authenti...
CVE-2026-24855MEDIUM5.4ChurchCRM is an open-source church management system. Versions prior to 6.7.2 have a Stored Cross-Site Scripting (XSS) v...
CVE-2026-1685MEDIUM5.9A vulnerability was identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_40AC74 of the comp...
CVE-2026-22626MEDIUM4.9Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can...
CVE-2026-22625MEDIUM4.6Improper handling of filenames in certain HIKSEMI NAS products may lead to the exposure of sensitive system files.
CVE-2026-22624MEDIUM4.3Due to inadequate access control, authenticated users of certain HIKSEMI NAS products can manipulate other users' file r...
CVE-2026-1665MEDIUM5.4A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() fun...
CVE-2026-24904MEDIUM5.3TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now