2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38669 | MEDIUM | 6.1 | 0.1% | May 4, 2026 | wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog. |
| CVE-2026-37461 | HIGH | 7.5 | 0.3% | May 4, 2026 | An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial ... |
| CVE-2026-29514 | HIGH | 8.8 | 0.8% | May 4, 2026 | NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environ... |
| CVE-2026-26956 | CRITICAL | 9.8 | 0.9% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary... |
| CVE-2026-26332 | CRITICAL | 10 | 0.7% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sa... |
| CVE-2026-25293 | CRITICAL | 9.8 | 0.2% | May 4, 2026 | Buffer overflow due to incorrect authorization in PLC FW |
| CVE-2026-25266 | HIGH | 7.8 | 0.1% | May 4, 2026 | Memory corruption while processing IOCTL command when device is in power-save state. |
| CVE-2026-24781 | CRITICAL | 9.8 | 1.2% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability... |
| CVE-2026-24120 | CRITICAL | 9.8 | 0.9% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and ca... |
| CVE-2026-24118 | CRITICAL | 9.8 | 0.9% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability... |
| CVE-2026-24082 | HIGH | 7.8 | 0.1% | May 4, 2026 | Memory Corruption when copying data from a freed source while executing performance counter deselect operation. |
| CVE-2026-40563 | HIGH | 8.1 | 0.5% | May 4, 2026 | Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas expose... |
| CVE-2026-37458 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat... |
| CVE-2026-36365 | HIGH | 7.8 | 0.1% | May 4, 2026 | An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker t... |
| CVE-2026-6501 | MEDIUM | 5.3 | 0.2% | May 4, 2026 | Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serial... |
| CVE-2026-6500 | MEDIUM | 4.8 | 0.1% | May 4, 2026 | Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. ... |
| CVE-2026-33523 | MEDIUM | 6.5 | 0.4% | May 4, 2026 | HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend serve... |
| CVE-2026-33007 | MEDIUM | 5.3 | 0.5% | May 4, 2026 | A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated r... |
| CVE-2026-33006 | MEDIUM | 4.8 | 0.6% | May 4, 2026 | A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remot... |
| CVE-2026-29169 | HIGH | 7.5 | 0.6% | May 4, 2026 | A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the s... |
| CVE-2026-23918 | HIGH | 8.8 | 45.8% | May 4, 2026 | Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HT... |
| CVE-2026-6499 | LOW | 2.4 | 0.1% | May 4, 2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Bina... |
| CVE-2026-6266 | HIGH | 8.3 | 0.4% | May 4, 2026 | A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external... |
| CVE-2026-4928 | — | — | — | May 4, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-34032 | MEDIUM | 5.3 | 0.5% | May 4, 2026 | Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Serve... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now