2026 CVE Vulnerabilities
45,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6920 | CRITICAL | 9.6 | 0.2% | Apr 23, 2026 | Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromi... |
| CVE-2026-6919 | CRITICAL | 9.6 | 0.3% | Apr 23, 2026 | Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the re... |
| CVE-2026-31533 | CRITICAL | 9.8 | 0.3% | Apr 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/tls: fix use-after-free in -EBUSY error path of... |
| CVE-2026-31181 | CRITICAL | 9.8 | 0.6% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31178 | CRITICAL | 9.8 | 0.6% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31177 | CRITICAL | 9.8 | 0.6% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-31175 | CRITICAL | 9.8 | 0.6% | Apr 23, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-40472 | CRITICAL | 9.9 | 0.3% | Apr 23, 2026 | In hackage-server, user-controlled metadata from .cabal files are rendered into HTML href attributes without proper sani... |
| CVE-2026-40471 | CRITICAL | 9.6 | 0.1% | Apr 23, 2026 | hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could ... |
| CVE-2026-40470 | CRITICAL | 9.9 | 0.3% | Apr 23, 2026 | A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in sou... |
| CVE-2026-23751 | CRITICAL | 9.8 | 0.9% | Apr 23, 2026 | Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecate... |
| CVE-2026-41460 | CRITICAL | 9.8 | 1.0% | Apr 23, 2026 | SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoin... |
| CVE-2026-39440 | CRITICAL | 9.9 | 0.4% | Apr 23, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote ... |
| CVE-2026-6887 | CRITICAL | 9.8 | 0.4% | Apr 23, 2026 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vulnerability, allowing... |
| CVE-2026-6886 | CRITICAL | 9.8 | 0.5% | Apr 23, 2026 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication Bypass vulnerability, ... |
| CVE-2026-6885 | CRITICAL | 9.8 | 0.5% | Apr 23, 2026 | Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File Upload vulnerability,... |
| CVE-2026-3960 | CRITICAL | 9.8 | 0.9% | Apr 23, 2026 | A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O... |
| CVE-2026-41229 | CRITICAL | 9.1 | 0.5% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes ... |
| CVE-2026-41228 | CRITICAL | 9.9 | 0.5% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.updat... |
| CVE-2026-3844 | CRITICAL | 9.8 | 36.5% | Apr 23, 2026 | The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the... |
| CVE-2026-41679 | CRITICAL | 10 | 2.0% | Apr 23, 2026 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 202... |
| CVE-2026-41211 | CRITICAL | 10 | 0.3% | Apr 23, 2026 | Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` ac... |
| CVE-2026-41197 | CRITICAL | 9.3 | 0.4% | Apr 23, 2026 | Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system,... |
| CVE-2026-41196 | CRITICAL | 10 | 0.4% | Apr 23, 2026 | Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to versio... |
| CVE-2026-5935 | CRITICAL | 9.8 | 0.3% | Apr 23, 2026 | IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now