2026 CVE Vulnerabilities
43,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12982 | MEDIUM | 6.1 | — | Jul 27, 2026 | The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it... |
| CVE-2026-10082 | MEDIUM | 6.1 | — | Jul 27, 2026 | The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it... |
| CVE-2026-17501 | MEDIUM | 6.9 | 0.4% | Jul 27, 2026 | A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file commo... |
| CVE-2026-17500 | MEDIUM | 6.9 | — | Jul 27, 2026 | A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file... |
| CVE-2026-57978 | MEDIUM | 5.4 | 0.2% | Jul 26, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne... |
| CVE-2026-17459 | MEDIUM | 4.3 | 0.3% | Jul 26, 2026 | A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.exter... |
| CVE-2026-17458 | MEDIUM | 6.3 | 0.2% | Jul 26, 2026 | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file s... |
| CVE-2026-17457 | MEDIUM | 4.3 | 0.3% | Jul 26, 2026 | A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserN... |
| CVE-2026-17434 | MEDIUM | 6.3 | 0.2% | Jul 26, 2026 | A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/mod... |
| CVE-2026-17433 | MEDIUM | 5.3 | 0.1% | Jul 26, 2026 | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of t... |
| CVE-2026-17432 | MEDIUM | 5 | 0.2% | Jul 26, 2026 | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functio... |
| CVE-2026-64297 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: module: decompress: check return value of module_ex... |
| CVE-2026-64295 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm: page_ext: add count limit to page_ext_iter_next... |
| CVE-2026-64294 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm: do file ownership checks with the proper mount ... |
| CVE-2026-64292 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Move vevent memory allocation outside spin... |
| CVE-2026-64291 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Set veventq_depth upper bound iommufd_vev... |
| CVE-2026-64290 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Break the loop on failure in iommufd_fault... |
| CVE-2026-64267 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse: avoid 32-bit prune notification count wrap F... |
| CVE-2026-64264 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix EFAULT clobber in fuse_uring_commit... |
| CVE-2026-64263 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix moving cancelled entry to ent_in_us... |
| CVE-2026-64262 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse-uring: end fuse_req on io-uring cancel task wo... |
| CVE-2026-64258 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: fuse-uring: remove request-less entries from ent_w_... |
| CVE-2026-64256 | MEDIUM | 5.5 | 0.2% | Jul 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: don't wrap around quota ids in dqiterate LOLL... |
| CVE-2026-15425 | MEDIUM | 6.4 | 0.2% | Jul 25, 2026 | The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2026-14955 | MEDIUM | 6.5 | 0.5% | Jul 25, 2026 | The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all version... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now