2026 CVE Vulnerabilities
64,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6968 | MEDIUM | 6.5 | 0.5% | Apr 24, 2026 | Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated si... |
| CVE-2026-6967 | MEDIUM | 6.5 | 0.2% | Apr 24, 2026 | Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 ... |
| CVE-2026-6966 | MEDIUM | 6.5 | 0.3% | Apr 24, 2026 | Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v... |
| CVE-2026-41503 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea... |
| CVE-2026-41502 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an off-by-one out-of... |
| CVE-2026-41477 | HIGH | 7.8 | 0.2% | Apr 24, 2026 | Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and ex... |
| CVE-2026-41476 | HIGH | 8.8 | 0.3% | Apr 24, 2026 | Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.138, a remote memory-safety vulnerability in Deskflow's c... |
| CVE-2026-41475 | CRITICAL | 9.1 | 0.5% | Apr 24, 2026 | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, an out-of-bounds rea... |
| CVE-2026-41433 | HIGH | 8.4 | 0.2% | Apr 24, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to befo... |
| CVE-2026-41429 | HIGH | 8.8 | 0.3% | Apr 24, 2026 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr... |
| CVE-2026-41428 | CRITICAL | 9.1 | 0.4% | Apr 24, 2026 | Budibase is an open-source low-code platform. Prior to 3.35.4, the authenticated middleware uses unanchored regular expr... |
| CVE-2026-41427 | MEDIUM | 6.5 | 0.2% | Apr 24, 2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option d... |
| CVE-2026-41426 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered e... |
| CVE-2026-41425 | MEDIUM | 5.4 | 0.1% | Apr 24, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection ... |
| CVE-2026-41244 | MEDIUM | 4.7 | 0.1% | Apr 24, 2026 | Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the Ci... |
| CVE-2026-41907 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | uuid is for the creation of RFC9562 (formerly RFC4122) UUIDs. Prior to 14.0.0, v3, v5, and v6 accept external output buf... |
| CVE-2026-41894 | HIGH | 7.1 | 0.3% | Apr 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a d... |
| CVE-2026-41492 | CRITICAL | 9.8 | 2.2% | Apr 24, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, Dgraphl exposes the process command line through... |
| CVE-2026-41421 | HIGH | 8.8 | 0.1% | Apr 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messa... |
| CVE-2026-41419 | HIGH | 7.6 | 0.3% | Apr 24, 2026 | 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an ... |
| CVE-2026-41418 | MEDIUM | 5.3 | 0.2% | Apr 24, 2026 | 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumerat... |
| CVE-2026-41416 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an integer ... |
| CVE-2026-41415 | CRITICAL | 9.1 | 0.3% | Apr 24, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-b... |
| CVE-2026-41414 | HIGH | 7.4 | 0.3% | Apr 24, 2026 | Skim is a fuzzy finder designed to through files, lines, and commands. The generate-files job in .github/workflows/pr.ym... |
| CVE-2026-41328 | CRITICAL | 9.1 | 0.3% | Apr 24, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now