2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-37539 | CRITICAL | 9.8 | 0.5% | May 1, 2026 | Buffer overflow vulnerability in cannelloni v2.0.0 in CAN frame parsing in parser.cpp in function parseCANFrame, and dec... |
| CVE-2026-37538 | HIGH | 7.5 | 0.3% | May 1, 2026 | Buffer overflow vulnerability in socketcand 0.4.2 in file socketcand.c in function main allows attackers to cause a deni... |
| CVE-2026-37537 | HIGH | 8.1 | 0.2% | May 1, 2026 | collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow ... |
| CVE-2026-37536 | HIGH | 8.8 | 0.3% | May 1, 2026 | miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diag... |
| CVE-2026-37535 | HIGH | 7.1 | 0.2% | May 1, 2026 | openxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6f5d46ac (2021-08-09) contains an out-of-bounds read in the I... |
| CVE-2026-37534 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | Integer underflow vulnerability in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in S... |
| CVE-2026-37532 | HIGH | 7.1 | 0.2% | May 1, 2026 | AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_re... |
| CVE-2026-37531 | CRITICAL | 9.8 | 0.7% | May 1, 2026 | AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU rac... |
| CVE-2026-37530 | HIGH | 7.5 | 0.4% | May 1, 2026 | AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_re... |
| CVE-2026-37526 | HIGH | 7.8 | 0.1% | May 1, 2026 | AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision comman... |
| CVE-2026-37525 | HIGH | 7.8 | 0.1% | May 1, 2026 | AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision ... |
| CVE-2026-7586 | MEDIUM | 4.3 | 0.3% | May 1, 2026 | A weakness has been identified in Open5GS up to 2.7.7. Affected is the function ogs_id_get_value of the file /src/amf/nu... |
| CVE-2026-7585 | MEDIUM | 4.3 | 0.3% | May 1, 2026 | A vulnerability was determined in Open5GS up to 2.7.7. The impacted element is the function amf_nudm_sdm_handle_provisio... |
| CVE-2026-42481 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can b... |
| CVE-2026-42480 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology... |
| CVE-2026-42475 | MEDIUM | 6.5 | 0.2% | May 1, 2026 | SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHe... |
| CVE-2026-42474 | MEDIUM | 6.5 | 0.2% | May 1, 2026 | SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `data` array to the data function in BuildHe... |
| CVE-2026-42473 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize... |
| CVE-2026-42472 | CRITICAL | 9.8 | 0.4% | May 1, 2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize... |
| CVE-2026-42471 | HIGH | 8.1 | 1.8% | May 1, 2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) cal... |
| CVE-2026-37554 | HIGH | 7.5 | 0.4% | May 1, 2026 | An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The v... |
| CVE-2026-37552 | HIGH | 8.4 | 0.3% | May 1, 2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) rec... |
| CVE-2026-37505 | MEDIUM | 4.9 | 0.2% | May 1, 2026 | SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort para... |
| CVE-2026-37504 | HIGH | 7.5 | 0.3% | May 1, 2026 | Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyControlle... |
| CVE-2026-37503 | MEDIUM | 4.8 | 0.2% | May 1, 2026 | Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now