2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42484 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a d... |
| CVE-2026-42483 | CRITICAL | 9.8 | 0.3% | May 1, 2026 | A heap-based buffer overflow in the Kerberos hash parser in hashcat v7.1.2 allows an attacker to cause a denial of servi... |
| CVE-2026-42482 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allow... |
| CVE-2026-31718 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in __ksmbd_close_fd() via... |
| CVE-2026-31705 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix out-of-bounds write in smb2_get_ea() EA ... |
| CVE-2026-42779 | CRITICAL | 9.8 | 0.9% | May 1, 2026 | The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: ... |
| CVE-2026-42778 | CRITICAL | 9.8 | 0.7% | May 1, 2026 | The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: ... |
| CVE-2026-7567 | CRITICAL | 9.8 | 9.2% | May 1, 2026 | The Temporary Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.0.0. T... |
| CVE-2026-42996 | CRITICAL | 10 | 0.5% | May 1, 2026 | JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @AP... |
| CVE-2026-42994 | CRITICAL | 9.8 | 0.3% | May 1, 2026 | Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code.... |
| CVE-2026-7546 | CRITICAL | 9.8 | 0.8% | May 1, 2026 | A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the functi... |
| CVE-2026-7538 | CRITICAL | 9.8 | 1.8% | May 1, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function Vulnerability of... |
| CVE-2026-40687 | CRITICAL | 9.1 | 0.4% | Apr 30, 2026 | In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-... |
| CVE-2026-40685 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounter... |
| CVE-2026-2311 | CRITICAL | 9.8 | 0.2% | Apr 30, 2026 | IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI... |
| CVE-2026-39858 | CRITICAL | 10 | 0.5% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s... |
| CVE-2026-35051 | CRITICAL | 10 | 0.3% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authe... |
| CVE-2026-33447 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers... |
| CVE-2026-33446 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attack... |
| CVE-2026-33845 | CRITICAL | 9.1 | 0.8% | Apr 30, 2026 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an i... |
| CVE-2026-36767 | CRITICAL | 10 | 0.4% | Apr 30, 2026 | A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary f... |
| CVE-2026-36760 | CRITICAL | 9.6 | 0.4% | Apr 30, 2026 | An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with ... |
| CVE-2026-4670 | CRITICAL | 9.8 | 5.6% | Apr 30, 2026 | Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Byp... |
| CVE-2026-42799 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associa... |
| CVE-2026-22070 | CRITICAL | 9.8 | 0.2% | Apr 30, 2026 | ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now