2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7403 | MEDIUM | 5.5 | 0.6% | Apr 29, 2026 | A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the fil... |
| CVE-2026-1858 | MEDIUM | 4.8 | 0.2% | Apr 29, 2026 | wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromis... |
| CVE-2026-7426 | HIGH | 8.1 | 0.2% | Apr 29, 2026 | Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V... |
| CVE-2026-7425 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.... |
| CVE-2026-7401 | MEDIUM | 4.3 | 0.3% | Apr 29, 2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulne... |
| CVE-2026-7400 | HIGH | 7.3 | 0.4% | Apr 29, 2026 | A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is... |
| CVE-2026-34965 | HIGH | 8.8 | 0.8% | Apr 29, 2026 | Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection en... |
| CVE-2026-7466 | HIGH | 8.8 | 0.3% | Apr 29, 2026 | AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline file... |
| CVE-2026-7439 | MEDIUM | 4.8 | 0.1% | Apr 29, 2026 | AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without... |
| CVE-2026-7424 | HIGH | 8.1 | 0.2% | Apr 29, 2026 | Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent netwo... |
| CVE-2026-7423 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adj... |
| CVE-2026-7422 | HIGH | 7.1 | 0.2% | Apr 29, 2026 | Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass ... |
| CVE-2026-7398 | HIGH | 7.3 | 0.4% | Apr 29, 2026 | A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulne... |
| CVE-2026-7397 | MEDIUM | 4.4 | 0.1% | Apr 29, 2026 | A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path ... |
| CVE-2026-41499 | MEDIUM | 6.5 | 0.3% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo... |
| CVE-2026-30893 | CRITICAL | 9.9 | 0.4% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to befo... |
| CVE-2026-28221 | HIGH | 8.2 | 0.4% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to befo... |
| CVE-2026-27105 | HIGH | 7.1 | 0.1% | Apr 29, 2026 | Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link... |
| CVE-2026-26206 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo... |
| CVE-2026-7396 | MEDIUM | 5.5 | 0.5% | Apr 29, 2026 | A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality ... |
| CVE-2026-7394 | MEDIUM | 4.7 | 0.2% | Apr 29, 2026 | A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2026-5712 | HIGH | 8.8 | 0.2% | Apr 29, 2026 | This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assi... |
| CVE-2026-26204 | MEDIUM | 5.5 | 0.2% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to befo... |
| CVE-2026-26015 | CRITICAL | 9.8 | 1.2% | Apr 29, 2026 | DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing bot... |
| CVE-2026-7393 | MEDIUM | 4.7 | 0.3% | Apr 29, 2026 | A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now