2026 CVE Vulnerabilities

43,090 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14859The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a...
CVE-2026-14858The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi...
CVE-2026-14857The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his...
CVE-2026-13613The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using ...
CVE-2026-13612The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al...
CVE-2026-13177The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user...
CVE-2026-13171The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han...
CVE-2026-13168The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users...
CVE-2026-12976The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a...
CVE-2026-64954HIGH8.2Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th...
CVE-2026-12235MEDIUM6.3The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (p...
CVE-2026-12234HIGH7.8The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn...
CVE-2026-12233MEDIUM5.9The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre...
CVE-2026-12232MEDIUM6.1The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a cal...
CVE-2026-9318MEDIUM5.4tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows...
CVE-2026-19588MEDIUM6.5Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
CVE-2026-19587MEDIUM6.5Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
CVE-2026-18961HIGH8.1The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera...
CVE-2026-73122HIGH7.7A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln...
CVE-2026-72526CRITICAL9.9A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man...
CVE-2026-70398CRITICAL9.6A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil...
CVE-2026-66878HIGH7.7A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable...
CVE-2026-64927MEDIUM6.4A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissio...
CVE-2026-6484HIGH8.2In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
CVE-2026-68450In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now