2026 CVE Vulnerabilities
45,065 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24120 | CRITICAL | 9.8 | 0.9% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and ca... |
| CVE-2026-24118 | CRITICAL | 9.8 | 0.9% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability... |
| CVE-2026-7482 | CRITICAL | 9.1 | 1.0% | May 4, 2026 | Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint... |
| CVE-2026-7747 | CRITICAL | 9.8 | 0.6% | May 4, 2026 | A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function l... |
| CVE-2026-29200 | CRITICAL | 9.9 | 0.3% | May 4, 2026 | A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2... |
| CVE-2026-7719 | CRITICAL | 9.8 | 0.6% | May 4, 2026 | A security flaw has been discovered in Totolink WA300 5.2cu.7112_B20190227. The affected element is the function loginau... |
| CVE-2026-7372 | CRITICAL | 9 | 0.5% | May 4, 2026 | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A special... |
| CVE-2026-7161 | CRITICAL | 9.3 | 0.2% | May 4, 2026 | An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Uti... |
| CVE-2026-42370 | CRITICAL | 9.8 | 0.5% | May 4, 2026 | A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A special... |
| CVE-2026-42369 | CRITICAL | 10 | 0.5% | May 4, 2026 | GV-VMS V20 is a Video Monitoring Software used to gather the feeds of many surveillance cameras and manage other securit... |
| CVE-2026-42368 | CRITICAL | 9.9 | 0.3% | May 4, 2026 | A privilege escalation vulnerability exists in the Web Interface functionality of GeoVision LPC2011/LPC2211 1.10. A spec... |
| CVE-2026-7690 | CRITICAL | 9.8 | 5.0% | May 3, 2026 | A weakness has been identified in Wavlink WL-WN570HA1 R70HA1 V1410_221110. This issue affects the function set_sys_adm o... |
| CVE-2026-7458 | CRITICAL | 9.8 | 0.6% | May 2, 2026 | The User Verification by PickPlugins plugin for WordPress is vulnerable to authentication bypass in all versions up to, ... |
| CVE-2026-4882 | CRITICAL | 9.8 | 0.7% | May 2, 2026 | The User Registration Advanced Fields plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t... |
| CVE-2026-37541 | CRITICAL | 10 | 0.7% | May 1, 2026 | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length fi... |
| CVE-2026-37540 | CRITICAL | 9.8 | 0.3% | May 1, 2026 | OpenAMP v2025.10.0 ELF loader contains an integer overflow vulnerability in firmware image parsing. In elf_loader.c, it ... |
| CVE-2026-37539 | CRITICAL | 9.8 | 0.5% | May 1, 2026 | Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and dec... |
| CVE-2026-37534 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in S... |
| CVE-2026-37531 | CRITICAL | 9.8 | 0.7% | May 1, 2026 | AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU rac... |
| CVE-2026-42473 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize... |
| CVE-2026-42472 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize... |
| CVE-2026-43039 | CRITICAL | 9.8 | 0.3% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix missing data copy and wr... |
| CVE-2026-43038 | CRITICAL | 9.8 | 0.3% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_... |
| CVE-2026-43037 | CRITICAL | 9.8 | 0.6% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar... |
| CVE-2026-43011 | CRITICAL | 9.8 | 0.5% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When all... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now