2026 CVE Vulnerabilities
64,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6979 | MEDIUM | 6.3 | 0.3% | Apr 25, 2026 | A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.con... |
| CVE-2026-6978 | MEDIUM | 4.7 | 0.3% | Apr 25, 2026 | A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of th... |
| CVE-2026-6977 | HIGH | 7.3 | 0.3% | Apr 25, 2026 | A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of... |
| CVE-2026-31685 | CRITICAL | 9.4 | 0.3% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_eui64: reject invalid MAC header fo... |
| CVE-2026-31684 | MEDIUM | 5.5 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: sched: act_csum: validate nested VLAN headers ... |
| CVE-2026-31683 | HIGH | 7.8 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: avoid OGM aggregation when skb tailroom... |
| CVE-2026-31682 | CRITICAL | 9.1 | 0.4% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: bridge: br_nd_send: linearize skb before parsing ND... |
| CVE-2026-31681 | MEDIUM | 5.5 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in... |
| CVE-2026-31680 | HIGH | 7.8 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ipv6: flowlabel: defer exclusive option free u... |
| CVE-2026-31679 | HIGH | 7.1 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: validate MPLS set/set_masked payload l... |
| CVE-2026-31678 | HIGH | 7.8 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: defer tunnel netdev_put to RCU release... |
| CVE-2026-31677 | MEDIUM | 5.5 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive ... |
| CVE-2026-31676 | HIGH | 7.5 | 0.4% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: only handle RESPONSE during service challeng... |
| CVE-2026-31675 | HIGH | 7.8 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_netem: fix out-of-bounds access in p... |
| CVE-2026-31674 | HIGH | 7.1 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_rt: reject oversized addrnr in rt_m... |
| CVE-2026-31673 | HIGH | 7.8 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: af_unix: read UNIX_DIAG_VFS data under unix_state_l... |
| CVE-2026-6951 | CRITICAL | 9.8 | 0.9% | Apr 25, 2026 | Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix ... |
| CVE-2026-6175 | — | — | — | Apr 24, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-42171 | HIGH | 7.8 | 0.2% | Apr 24, 2026 | NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as ... |
| CVE-2026-41488 | LOW | 3.1 | 0.2% | Apr 24, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.1.14, langchain-openai's _url_to_s... |
| CVE-2026-41481 | MEDIUM | 6.5 | 0.3% | Apr 24, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTM... |
| CVE-2026-41478 | CRITICAL | 9.9 | 0.3% | Apr 24, 2026 | Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.6, 1.5.6, and 1.6.0-beta.5, a... |
| CVE-2026-41473 | CRITICAL | 9.1 | 0.8% | Apr 24, 2026 | CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints... |
| CVE-2026-41472 | MEDIUM | 6.1 | 0.5% | Apr 24, 2026 | CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where... |
| CVE-2026-41248 | CRITICAL | 9.1 | 0.3% | Apr 24, 2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now