2026 CVE Vulnerabilities

43,308 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-17527HIGH7.7In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only acc...
CVE-2026-17523HIGH7.8A flaw was found in the Linux kernel in net/can/bcm.c in can: bcm, where an unprivileged local user can exploit this vul...
CVE-2026-65894HIGH8.7This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper authentication of HTTP endpoints. A remote attacke...
CVE-2026-65893HIGH7This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An atta...
CVE-2026-64536HIGH8.1In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip(...
CVE-2026-64533HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conver...
CVE-2026-64532HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateReco...
CVE-2026-64531HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action at...
CVE-2026-14837HIGH8.5Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism...
CVE-2026-9830HIGH8.2The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission cal...
CVE-2026-66412HIGH7.1Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston...
CVE-2026-14235HIGH7.5The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session...
CVE-2026-13726HIGH7.1The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the respons...
CVE-2026-13152HIGH8.1The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registrat...
CVE-2026-12493HIGH7.5The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext...
CVE-2026-12255HIGH8.1The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques...
CVE-2026-15928HIGH8.2XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in...
CVE-2026-57990HIGH7.4Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t...
CVE-2026-57989HIGH7.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ...
CVE-2026-17497HIGH8.3NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar...
CVE-2026-17496HIGH8.1NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t...
CVE-2026-63720HIGH7.5datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who contr...
CVE-2026-15962HIGH8.8The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i...
CVE-2026-10681HIGH7In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thre...
CVE-2026-64529HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: qat - remove unused character device and IO...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now