2026 CVE Vulnerabilities
43,896 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54849 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. |
| CVE-2026-54843 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. |
| CVE-2026-54836 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows ... |
| CVE-2026-54823 | CRITICAL | 9.9 | 0.4% | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. |
| CVE-2026-41120 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust... |
| CVE-2026-53260 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk... |
| CVE-2026-53247 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in m... |
| CVE-2026-53246 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COO... |
| CVE-2026-53228 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offlo... |
| CVE-2026-53225 | CRITICAL | 9.1 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup(... |
| CVE-2026-53224 | CRITICAL | 9.1 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list... |
| CVE-2026-53221 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_... |
| CVE-2026-53216 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer ... |
| CVE-2026-53215 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use... |
| CVE-2026-53186 | CRITICAL | 9.1 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received ... |
| CVE-2026-53176 | CRITICAL | 9.8 | 0.7% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADE... |
| CVE-2026-53175 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir... |
| CVE-2026-53151 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table... |
| CVE-2026-53131 | CRITICAL | 9.4 | 0.4% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using... |
| CVE-2026-46752 | CRITICAL | 10 | 0.4% | Jun 25, 2026 | Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4... |
| CVE-2026-41566 | CRITICAL | 9.4 | 0.3% | Jun 25, 2026 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache ... |
| CVE-2026-8666 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows r... |
| CVE-2026-8665 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote att... |
| CVE-2026-8660 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attack... |
| CVE-2026-8592 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now