2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31693 | HIGH | 7.8 | 0.1% | Apr 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In se... |
| CVE-2026-1493 | MEDIUM | 5.4 | 0.2% | Apr 30, 2026 | LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the para... |
| CVE-2026-31787 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting pri... |
| CVE-2026-31786 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c Th... |
| CVE-2026-31692 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check f... |
| CVE-2026-6498 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in ve... |
| CVE-2026-42800 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Mani... |
| CVE-2026-41016 | MEDIUM | 5.9 | 0.3% | Apr 30, 2026 | Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certif... |
| CVE-2026-42799 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associa... |
| CVE-2026-42512 | HIGH | 8.1 | 1.4% | Apr 30, 2026 | As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. ... |
| CVE-2026-39457 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whethe... |
| CVE-2026-35547 | HIGH | 8.1 | 0.3% | Apr 30, 2026 | When processing the header of an incoming message, libnv failed to properly validate the message size. The lack of vali... |
| CVE-2026-22070 | CRITICAL | 9.8 | 0.2% | Apr 30, 2026 | ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. |
| CVE-2026-7164 | HIGH | 7.5 | 0.4% | Apr 30, 2026 | Incorrect packet validation allowed unbounded recursion parsing SCTP chunk parameters. This can eventually result in a ... |
| CVE-2026-7270 | HIGH | 7.8 | 0.2% | Apr 30, 2026 | An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data t... |
| CVE-2026-6870 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6869 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6867 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6538 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6537 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6536 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 |
| CVE-2026-6535 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6534 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6533 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-6532 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now