2026 CVE Vulnerabilities

43,896 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-54849CRITICAL9.3Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.
CVE-2026-54843CRITICAL9.3Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
CVE-2026-54836CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows ...
CVE-2026-54823CRITICAL9.9Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
CVE-2026-41120CRITICAL9.8Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust...
CVE-2026-53260CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk...
CVE-2026-53247CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in m...
CVE-2026-53246CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COO...
CVE-2026-53228CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offlo...
CVE-2026-53225CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup(...
CVE-2026-53224CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list...
CVE-2026-53221CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_...
CVE-2026-53216CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer ...
CVE-2026-53215CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use...
CVE-2026-53186CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received ...
CVE-2026-53176CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADE...
CVE-2026-53175CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir...
CVE-2026-53151CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table...
CVE-2026-53131CRITICAL9.4In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using...
CVE-2026-46752CRITICAL10Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4...
CVE-2026-41566CRITICAL9.4Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache ...
CVE-2026-8666CRITICAL9.8OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows r...
CVE-2026-8665CRITICAL9.8OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote att...
CVE-2026-8660CRITICAL9.8OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attack...
CVE-2026-8592CRITICAL9.8OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now