2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-38669MEDIUM6.1wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.
CVE-2026-37461HIGH7.5An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial ...
CVE-2026-29514HIGH8.8NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environ...
CVE-2026-26956CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary...
CVE-2026-26332CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sa...
CVE-2026-25293CRITICAL9.8Buffer overflow due to incorrect authorization in PLC FW
CVE-2026-25266HIGH7.8Memory corruption while processing IOCTL command when device is in power-save state.
CVE-2026-24781CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability...
CVE-2026-24120CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and ca...
CVE-2026-24118CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability...
CVE-2026-24082HIGH7.8Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
CVE-2026-40563HIGH8.1Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas expose...
CVE-2026-37458MEDIUM6.5Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat...
CVE-2026-36365HIGH7.8An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker t...
CVE-2026-6501MEDIUM5.3Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serial...
CVE-2026-6500MEDIUM4.8Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. ...
CVE-2026-33523MEDIUM6.5HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend serve...
CVE-2026-33007MEDIUM5.3A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated r...
CVE-2026-33006MEDIUM4.8A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remot...
CVE-2026-29169HIGH7.5A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the s...
CVE-2026-23918HIGH8.8Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HT...
CVE-2026-6499LOW2.4Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Bina...
CVE-2026-6266HIGH8.3A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external...
CVE-2026-4928——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-34032MEDIUM5.3Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Serve...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now