2026 CVE Vulnerabilities
53,423 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23011 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: ip_gre: make ipgre_header() robust Analog to... |
| CVE-2026-23009 | MEDIUM | 5.5 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: xhci: sideband: don't dereference freed ring when r... |
| CVE-2026-23008 | MEDIUM | 5.5 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix KMS with 3D on HW version 10 HW ve... |
| CVE-2026-23007 | MEDIUM | 5.5 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: block: zero non-PI portion of auto integrity buffer... |
| CVE-2026-23006 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ASoC: tlv320adcx140: fix null pointer The "snd_soc... |
| CVE-2026-23005 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Clear XSTATE_BV[i] in guest XSAVE state wh... |
| CVE-2026-23004 | MEDIUM | 4.7 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: dst: fix races in rt6_uncached_list_del() and rt_de... |
| CVE-2026-23003 | MEDIUM | 5.5 | 0.5% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tn... |
| CVE-2026-23002 | MEDIUM | 5.5 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: lib/buildid: use __kernel_read() for sleepable cont... |
| CVE-2026-23000 | MEDIUM | 5.5 | 0.1% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix crash on profile change rollback fai... |
| CVE-2026-22999 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: do not free existing class in q... |
| CVE-2026-22997 | MEDIUM | 5.5 | 0.4% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: can: j1939: j1939_xtp_rx_rts_session_active():... |
| CVE-2026-22996 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devl... |
| CVE-2026-0593 | MEDIUM | 5.3 | 0.2% | Jan 24, 2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2026-0862 | MEDIUM | 6.1 | 0.2% | Jan 24, 2026 | The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘options... |
| CVE-2026-1302 | MEDIUM | 4.4 | 0.2% | Jan 24, 2026 | The Meta-box GalleryMeta plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ver... |
| CVE-2026-1300 | MEDIUM | 4.4 | 0.2% | Jan 24, 2026 | The Responsive Header plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple plugin settings par... |
| CVE-2026-1266 | MEDIUM | 4.4 | 0.2% | Jan 24, 2026 | The Postalicious plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up... |
| CVE-2026-1208 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2026-1191 | MEDIUM | 4.4 | 0.2% | Jan 24, 2026 | The JavaScript Notifier plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all ver... |
| CVE-2026-1189 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The LeadBI Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_id' para... |
| CVE-2026-1127 | MEDIUM | 6.1 | 0.2% | Jan 24, 2026 | The Timeline Event History plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `id` parameter i... |
| CVE-2026-1098 | MEDIUM | 6.4 | 0.2% | Jan 24, 2026 | The CM CSS Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' shortcode attribute i... |
| CVE-2026-0687 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The Meta-box GalleryMeta plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2026-1103 | MEDIUM | 5.4 | 0.2% | Jan 24, 2026 | The AIKTP plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now