2026 CVE Vulnerabilities

53,439 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-24140MEDIUM5.3MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignme...
CVE-2026-24139MEDIUM6.5MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard aga...
CVE-2026-24128MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-mi...
CVE-2026-24127MEDIUM6.1Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Sc...
CVE-2026-1386MEDIUM6A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on L...
CVE-2026-1299MEDIUM6The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when seria...
CVE-2026-22994MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reference count leak in bpf_prog_test_run_...
CVE-2026-22993MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: idpf: Fix RSS LUT NULL ptr issue after soft reset ...
CVE-2026-22992MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: libceph: return the handler error from mon_handle_a...
CVE-2026-22991MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: libceph: make free_choose_arg_map() resilient to pa...
CVE-2026-22990MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: libceph: replace overzealous BUG_ON in osdmap_apply...
CVE-2026-22989MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: check that server is running in unlock_filesy...
CVE-2026-22988MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arp: do not assume dev_hard_header() does not chang...
CVE-2026-22987MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: avoid dereferencing ERR_PTR in ...
CVE-2026-22986MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix race condition for gdev->srcu If two ...
CVE-2026-22985MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: idpf: Fix RSS LUT NULL pointer crash on early ethto...
CVE-2026-22983MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: do not write to msg_get_inq in callee NULL po...
CVE-2026-22982MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: Fix crash when adding interface ...
CVE-2026-22981MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: idpf: detach and close netdevs while handling a res...
CVE-2026-22979MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: fix memory leak in skb_segment_list for GRO pa...
CVE-2026-24636MEDIUM4.3Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrect...
CVE-2026-24634MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Ultimate Reviews ultimate-reviews allows Ex...
CVE-2026-24633MEDIUM5.3Missing Authorization vulnerability in Passionate Brains Add Expires Headers & Optimized Minify add-expires-headers allo...
CVE-2026-24632MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jagdish1o1 Delay R...
CVE-2026-24631MEDIUM5.4Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Rosebud rosebud allows Exploiting Incorr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now