2026 CVE Vulnerabilities
64,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41327 | CRITICAL | 9.1 | 0.4% | Apr 24, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi... |
| CVE-2026-41326 | HIGH | 8.2 | 0.3% | Apr 24, 2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th... |
| CVE-2026-33666 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.... |
| CVE-2026-33662 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-33524 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.... |
| CVE-2026-42044 | CRITICAL | 9.1 | 0.6% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulne... |
| CVE-2026-42043 | CRITICAL | 10 | 0.7% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influe... |
| CVE-2026-42042 | MEDIUM | 5.4 | 0.2% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF t... |
| CVE-2026-42041 | MEDIUM | 6.5 | 0.6% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulne... |
| CVE-2026-42040 | LOW | 3.7 | 0.2% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in l... |
| CVE-2026-42039 | HIGH | 7.5 | 0.7% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively wal... |
| CVE-2026-42038 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostna... |
| CVE-2026-42037 | MEDIUM | 5.3 | 0.2% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart construc... |
| CVE-2026-42036 | MEDIUM | 5.3 | 0.4% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream... |
| CVE-2026-42035 | HIGH | 7.4 | 0.4% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadg... |
| CVE-2026-42034 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies,... |
| CVE-2026-42033 | HIGH | 7.4 | 0.8% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has ... |
| CVE-2026-41898 | MEDIUM | 5.3 | 0.4% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampo... |
| CVE-2026-41681 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFin... |
| CVE-2026-41680 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists... |
| CVE-2026-41678 | HIGH | 8.1 | 0.3% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() co... |
| CVE-2026-41677 | CRITICAL | 9.1 | 0.3% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_... |
| CVE-2026-41676 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::deriv... |
| CVE-2026-41322 | MEDIUM | 5.3 | 0.2% | Apr 24, 2026 | @astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resource... |
| CVE-2026-41321 | LOW | 2.2 | 0.2% | Apr 24, 2026 | @astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now