2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27681 | CRITICAL | 9.9 | 0.5% | Apr 14, 2026 | Due to insufficient authorization checks in SAP Business Planning and Consolidation and SAP Business Warehouse, an authe... |
| CVE-2026-22564 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable S... |
| CVE-2026-22563 | CRITICAL | 9.8 | 1.1% | Apr 13, 2026 | A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access t... |
| CVE-2026-22562 | CRITICAL | 9.8 | 0.8% | Apr 13, 2026 | A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device... |
| CVE-2026-31048 | CRITICAL | 9.8 | 0.6% | Apr 13, 2026 | An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a cra... |
| CVE-2026-40044 | CRITICAL | 9.8 | 0.5% | Apr 13, 2026 | Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by... |
| CVE-2026-40042 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbit... |
| CVE-2026-6195 | CRITICAL | 9.8 | 14.3% | Apr 13, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the funct... |
| CVE-2026-6100 | CRITICAL | 9.1 | 0.6% | Apr 13, 2026 | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memo... |
| CVE-2026-31283 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address.... |
| CVE-2026-31282 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to revea... |
| CVE-2026-31414 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use expect->helper ... |
| CVE-2026-4810 | CRITICAL | 9.3 | 1.8% | Apr 13, 2026 | A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.... |
| CVE-2026-0234 | CRITICAL | 9.1 | 0.2% | Apr 13, 2026 | An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms duri... |
| CVE-2026-5936 | CRITICAL | 9.8 | 0.2% | Apr 13, 2026 | An attacker can control a server-side HTTP request by supplying a crafted URL, causing the server to initiate requests t... |
| CVE-2026-5085 | CRITICAL | 9.1 | 0.3% | Apr 13, 2026 | Solstice::Session versions through 1440 for Perl generates session ids insecurely. The _generateSessionID method return... |
| CVE-2026-34865 | CRITICAL | 9.1 | 0.2% | Apr 13, 2026 | Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av... |
| CVE-2026-40446 | CRITICAL | 9.8 | 0.2% | Apr 13, 2026 | Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Point... |
| CVE-2026-25209 | CRITICAL | 9.1 | 0.3% | Apr 13, 2026 | Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg... |
| CVE-2026-25208 | CRITICAL | 9.8 | 0.3% | Apr 13, 2026 | Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8... |
| CVE-2026-25207 | CRITICAL | 9.8 | 0.2% | Apr 13, 2026 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 9... |
| CVE-2026-25206 | CRITICAL | 9.1 | 0.2% | Apr 13, 2026 | Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escarg... |
| CVE-2026-25205 | CRITICAL | 9.8 | 0.2% | Apr 13, 2026 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects E... |
| CVE-2026-6156 | CRITICAL | 9.8 | 1.8% | Apr 13, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setIpQosR... |
| CVE-2026-6155 | CRITICAL | 9.8 | 1.8% | Apr 13, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313. The impacted element is the function setWanCfg of the fil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now