2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41471 | HIGH | 8.2 | 0.3% | May 4, 2026 | The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerabilit... |
| CVE-2026-37459 | HIGH | 7.5 | 0.4% | May 4, 2026 | An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2026-32834 | HIGH | 8.7 | 0.4% | May 4, 2026 | Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerab... |
| CVE-2026-2828 | — | — | — | May 4, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-29004 | HIGH | 8.1 | 0.4% | May 4, 2026 | BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS o... |
| CVE-2026-0073 | HIGH | 8.8 | 0.5% | May 4, 2026 | In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err... |
| CVE-2026-42812 | CRITICAL | 9.9 | 0.4% | May 4, 2026 | In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table ... |
| CVE-2026-42811 | CRITICAL | 9.9 | 0.4% | May 4, 2026 | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, bu... |
| CVE-2026-42810 | CRITICAL | 9.9 | 0.4% | May 4, 2026 | Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access pol... |
| CVE-2026-42809 | CRITICAL | 9.9 | 0.4% | May 4, 2026 | Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effectiv... |
| CVE-2026-42440 | HIGH | 7.5 | 0.6% | May 4, 2026 | OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before... |
| CVE-2026-42376 | CRITICAL | 9.8 | 0.5% | May 4, 2026 | D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet... |
| CVE-2026-42375 | HIGH | 8.8 | 0.5% | May 4, 2026 | D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daem... |
| CVE-2026-42374 | HIGH | 8.8 | 0.5% | May 4, 2026 | D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daem... |
| CVE-2026-42373 | HIGH | 8.8 | 0.5% | May 4, 2026 | D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet... |
| CVE-2026-42372 | HIGH | 8.8 | 0.3% | May 4, 2026 | D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet... |
| CVE-2026-42090 | CRITICAL | 9.6 | 0.5% | May 4, 2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and ... |
| CVE-2026-42080 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary fi... |
| CVE-2026-42079 | HIGH | 8.6 | 0.1% | May 4, 2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t... |
| CVE-2026-42078 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t... |
| CVE-2026-42077 | MEDIUM | 5.2 | 0.1% | May 4, 2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit... |
| CVE-2026-42076 | CRITICAL | 9.8 | 1.3% | May 4, 2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability ... |
| CVE-2026-42075 | HIGH | 8.1 | 0.6% | May 4, 2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in ... |
| CVE-2026-42027 | CRITICAL | 9.8 | 0.7% | May 4, 2026 | Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5,... |
| CVE-2026-40682 | CRITICAL | 9.1 | 0.5% | May 4, 2026 | XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affec... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now