2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7381 | CRITICAL | 9.1 | 0.4% | Apr 29, 2026 | Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middle... |
| CVE-2026-30893 | CRITICAL | 9.9 | 0.4% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to befo... |
| CVE-2026-26015 | CRITICAL | 9.8 | 1.2% | Apr 29, 2026 | DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing bot... |
| CVE-2026-5166 | CRITICAL | 9.6 | 0.3% | Apr 29, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software ... |
| CVE-2026-41940 | CRITICAL | 9.8 | 98.1% | Apr 29, 2026 | cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthe... |
| CVE-2026-38992 | CRITICAL | 9.8 | 0.4% | Apr 29, 2026 | Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints... |
| CVE-2026-36841 | CRITICAL | 9.8 | 1.1% | Apr 29, 2026 | TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in ... |
| CVE-2026-42523 | CRITICAL | 9 | 0.3% | Apr 29, 2026 | Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing val... |
| CVE-2026-42249 | CRITICAL | 9.8 | 0.6% | Apr 29, 2026 | Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of at... |
| CVE-2026-42248 | CRITICAL | 9.8 | 0.4% | Apr 29, 2026 | Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike othe... |
| CVE-2026-3325 | CRITICAL | 10 | 0.3% | Apr 29, 2026 | SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/ge... |
| CVE-2026-7333 | CRITICAL | 9.6 | 0.3% | Apr 28, 2026 | Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbo... |
| CVE-2026-41446 | CRITICAL | 9.8 | 0.4% | Apr 28, 2026 | Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints th... |
| CVE-2026-41397 | CRITICAL | 9.6 | 0.5% | Apr 28, 2026 | OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries th... |
| CVE-2026-41386 | CRITICAL | 9.8 | 0.3% | Apr 28, 2026 | OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to int... |
| CVE-2026-3893 | CRITICAL | 9.4 | 0.4% | Apr 28, 2026 | The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to direct... |
| CVE-2026-24178 | CRITICAL | 9.8 | 0.6% | Apr 28, 2026 | NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthentica... |
| CVE-2026-41873 | CRITICAL | 9.8 | 0.4% | Apr 28, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnera... |
| CVE-2026-7321 | CRITICAL | 9.6 | 0.3% | Apr 28, 2026 | Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in... |
| CVE-2026-27760 | CRITICAL | 9.2 | 22.2% | Apr 28, 2026 | OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows ... |
| CVE-2026-7248 | CRITICAL | 9.4 | 2.2% | Apr 28, 2026 | A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of t... |
| CVE-2026-7244 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiF... |
| CVE-2026-7243 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg... |
| CVE-2026-7242 | CRITICAL | 9.8 | 2.5% | Apr 28, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of ... |
| CVE-2026-7241 | CRITICAL | 9.8 | 2.4% | Apr 28, 2026 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now