2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6389 | HIGH | 7.8 | 0.1% | Apr 30, 2026 | IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cl... |
| CVE-2026-40687 | CRITICAL | 9.1 | 0.4% | Apr 30, 2026 | In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-... |
| CVE-2026-40686 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing character... |
| CVE-2026-40685 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounter... |
| CVE-2026-40684 | HIGH | 7.5 | 0.4% | Apr 30, 2026 | In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor... |
| CVE-2026-3345 | MEDIUM | 6.5 | 0.4% | Apr 30, 2026 | IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker c... |
| CVE-2026-2311 | CRITICAL | 9.8 | 0.2% | Apr 30, 2026 | IBM i 7.6, 7.5, 7.4, 7.3, and 7.2 s vulnerable to privilege escalation caused by an invalid IBM i Web Administration GUI... |
| CVE-2026-1577 | MEDIUM | 6.5 | 0.3% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2026-7501 | LOW | 3.5 | 0.3% | Apr 30, 2026 | A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/... |
| CVE-2026-7435 | HIGH | 8.6 | 0.4% | Apr 30, 2026 | SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed ... |
| CVE-2026-6539 | MEDIUM | 4.6 | 0.2% | Apr 30, 2026 | Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers... |
| CVE-2026-4503 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to... |
| CVE-2026-4502 | MEDIUM | 6.5 | 0.3% | Apr 30, 2026 | IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the s... |
| CVE-2026-41263 | LOW | 3.7 | 0.4% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a timing... |
| CVE-2026-41174 | MEDIUM | 6.4 | 0.3% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potent... |
| CVE-2026-40951 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with loc... |
| CVE-2026-40950 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of... |
| CVE-2026-40949 | MEDIUM | 4.4 | 0.1% | Apr 30, 2026 | CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo... |
| CVE-2026-40912 | HIGH | 8.2 | 0.8% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s... |
| CVE-2026-3346 | MEDIUM | 6.4 | 0.2% | Apr 30, 2026 | IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows... |
| CVE-2026-3340 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo... |
| CVE-2026-39858 | CRITICAL | 10 | 0.5% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s... |
| CVE-2026-35051 | CRITICAL | 10 | 0.3% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authe... |
| CVE-2026-33452 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo... |
| CVE-2026-33451 | HIGH | 7.8 | 0.1% | Apr 30, 2026 | CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers w... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now