2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6500 | MEDIUM | 4.8 | 0.1% | May 4, 2026 | Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. ... |
| CVE-2026-33523 | MEDIUM | 6.5 | 0.4% | May 4, 2026 | HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend serve... |
| CVE-2026-33007 | MEDIUM | 5.3 | 0.5% | May 4, 2026 | A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated r... |
| CVE-2026-33006 | MEDIUM | 4.8 | 0.6% | May 4, 2026 | A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remot... |
| CVE-2026-29169 | HIGH | 7.5 | 0.6% | May 4, 2026 | A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the s... |
| CVE-2026-23918 | HIGH | 8.8 | 45.8% | May 4, 2026 | Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HT... |
| CVE-2026-6499 | LOW | 2.4 | 0.1% | May 4, 2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Bina... |
| CVE-2026-6266 | HIGH | 8.3 | 0.4% | May 4, 2026 | A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external... |
| CVE-2026-4928 | — | — | — | May 4, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-34032 | MEDIUM | 5.3 | 0.5% | May 4, 2026 | Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Serve... |
| CVE-2026-33857 | MEDIUM | 5.3 | 0.4% | May 4, 2026 | Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: throu... |
| CVE-2026-31205 | MEDIUM | 5.7 | 0.3% | May 4, 2026 | Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via t... |
| CVE-2026-7482 | CRITICAL | 9.1 | 1.0% | May 4, 2026 | Ollama before 0.17.1 contains a heap out-of-bounds read vulnerability in the GGUF model loader. The /api/create endpoint... |
| CVE-2026-34059 | HIGH | 7.5 | 0.4% | May 4, 2026 | Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are... |
| CVE-2026-24072 | HIGH | 8.8 | 0.7% | May 4, 2026 | An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to re... |
| CVE-2026-3120 | HIGH | 7.2 | 1.2% | May 4, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and... |
| CVE-2026-7750 | HIGH | 8.8 | 0.5% | May 4, 2026 | A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRul... |
| CVE-2026-7749 | HIGH | 8.8 | 0.6% | May 4, 2026 | A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of... |
| CVE-2026-7748 | HIGH | 8.8 | 0.5% | May 4, 2026 | A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW o... |
| CVE-2026-33846 | HIGH | 7.5 | 1.3% | May 4, 2026 | A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises ... |
| CVE-2026-7747 | CRITICAL | 9.8 | 0.6% | May 4, 2026 | A security flaw has been discovered in Totolink N300RH 3.2.4-B20220812. Affected by this vulnerability is the function l... |
| CVE-2026-7746 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknow... |
| CVE-2026-7745 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineCl... |
| CVE-2026-7744 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassro... |
| CVE-2026-7743 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the fil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now