2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41328 | CRITICAL | 9.1 | 0.3% | Apr 24, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi... |
| CVE-2026-41327 | CRITICAL | 9.1 | 0.4% | Apr 24, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi... |
| CVE-2026-42044 | CRITICAL | 9.1 | 0.6% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulne... |
| CVE-2026-42043 | CRITICAL | 10 | 0.7% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influe... |
| CVE-2026-41677 | CRITICAL | 9.1 | 0.3% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_... |
| CVE-2026-6911 | CRITICAL | 9.8 | 0.3% | Apr 24, 2026 | Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain uninte... |
| CVE-2026-39920 | CRITICAL | 9.8 | 0.5% | Apr 24, 2026 | BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on net... |
| CVE-2026-31669 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_est... |
| CVE-2026-31668 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths... |
| CVE-2026-31659 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buf... |
| CVE-2026-31657 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by referen... |
| CVE-2026-31649 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: fix integer underflow in chain mode T... |
| CVE-2026-31637 | CRITICAL | 9.8 | 0.5% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: reject undecryptable rxkad response tickets ... |
| CVE-2026-31636 | CRITICAL | 9.1 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read ... |
| CVE-2026-31633 | CRITICAL | 9.8 | 0.5% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix integer overflow in rxgk_verify_response... |
| CVE-2026-31609 | CRITICAL | 9.8 | 0.5% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: avoid double-free in smbd_free_send_io... |
| CVE-2026-31608 | CRITICAL | 9.8 | 0.5% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: server: avoid double-free in smb_direct_free_s... |
| CVE-2026-31607 | CRITICAL | 9.8 | 0.3% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret... |
| CVE-2026-31589 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm: call ->free_folio() directly in folio_unmap_inv... |
| CVE-2026-31536 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: server: let send_done handle a completion with... |
| CVE-2026-25660 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2026-21515 | CRITICAL | 9.9 | 0.7% | Apr 24, 2026 | Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate... |
| CVE-2026-1951 | CRITICAL | 9.8 | 0.6% | Apr 24, 2026 | Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability. |
| CVE-2026-1950 | CRITICAL | 9.8 | 0.3% | Apr 24, 2026 | Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability. |
| CVE-2026-1949 | CRITICAL | 9.8 | 0.6% | Apr 24, 2026 | Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now