2026 CVE Vulnerabilities
64,935 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41140 | HIGH | 8.7 | 0.3% | Apr 24, 2026 | Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-... |
| CVE-2026-6912 | HIGH | 8.8 | 0.4% | Apr 24, 2026 | Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in... |
| CVE-2026-6911 | CRITICAL | 9.8 | 0.3% | Apr 24, 2026 | Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain uninte... |
| CVE-2026-41411 | MEDIUM | 6.6 | 0.5% | Apr 24, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's ta... |
| CVE-2026-41079 | MEDIUM | 5.4 | 0.4% | Apr 24, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a ... |
| CVE-2026-41067 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a... |
| CVE-2026-41066 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in... |
| CVE-2026-40897 | HIGH | 8.8 | 0.6% | Apr 24, 2026 | Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed e... |
| CVE-2026-40609 | — | — | — | Apr 24, 2026 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2026-39920 | CRITICAL | 9.8 | 0.5% | Apr 24, 2026 | BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on net... |
| CVE-2026-30368 | MEDIUM | 5.4 | 0.3% | Apr 24, 2026 | A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to i... |
| CVE-2026-42095 | MEDIUM | 4 | 0.2% | Apr 24, 2026 | bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL. |
| CVE-2026-31672 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lifetime USB drivers b... |
| CVE-2026-31671 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_report() struct ... |
| CVE-2026-31670 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill ev... |
| CVE-2026-31669 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_est... |
| CVE-2026-31668 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths... |
| CVE-2026-31667 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: Input: uinput - fix circular locking dependency wit... |
| CVE-2026-31666 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix incorrect return value after changing le... |
| CVE-2026-31665 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-after-free in timeout ob... |
| CVE-2026-31664 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() ... |
| CVE-2026-31663 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_... |
| CVE-2026-31662 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix bc_ackers underflow on duplicate GRP_ACK_... |
| CVE-2026-31661 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: Fix dma_free_coherent() size dma_a... |
| CVE-2026-31660 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: allocate rx skb before consuming bytes ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now