2026 CVE Vulnerabilities
64,982 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34066 | MEDIUM | 5.3 | 0.2% | Apr 22, 2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStor... |
| CVE-2026-34065 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prio... |
| CVE-2026-34064 | HIGH | 8.2 | 0.3% | Apr 22, 2026 | nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingCon... |
| CVE-2026-34063 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` disco... |
| CVE-2026-34062 | MEDIUM | 5.3 | 0.3% | Apr 22, 2026 | nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and... |
| CVE-2026-33471 | CRITICAL | 9.6 | 0.2% | Apr 22, 2026 | nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its q... |
| CVE-2026-41469 | MEDIUM | 5.2 | 0.2% | Apr 22, 2026 | Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaSc... |
| CVE-2026-41468 | CRITICAL | 9.3 | 0.4% | Apr 22, 2026 | Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives.... |
| CVE-2026-41459 | MEDIUM | 6.9 | 0.8% | Apr 22, 2026 | Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthentica... |
| CVE-2026-34415 | CRITICAL | 9.8 | 3.6% | Apr 22, 2026 | Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder con... |
| CVE-2026-34414 | HIGH | 7.1 | 2.8% | Apr 22, 2026 | Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connecto... |
| CVE-2026-34413 | HIGH | 8.8 | 2.8% | Apr 22, 2026 | Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector... |
| CVE-2026-28950 | MEDIUM | 6.2 | 2.9% | Apr 22, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.... |
| CVE-2026-26354 | CRITICAL | 9.8 | 0.5% | Apr 22, 2026 | Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2... |
| CVE-2026-6515 | MEDIUM | 5.4 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2026-5816 | HIGH | 8.1 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1... |
| CVE-2026-5377 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed ... |
| CVE-2026-5262 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, a... |
| CVE-2026-4922 | HIGH | 8.1 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2026-3254 | LOW | 3.5 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain condi... |
| CVE-2026-35382 | — | — | — | Apr 22, 2026 | Rejected reason: Voluntarily withdrawn |
| CVE-2026-35381 | LOW | 3.3 | 0.1% | Apr 22, 2026 | A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when usin... |
| CVE-2026-35380 | MEDIUM | 5.5 | 0.2% | Apr 22, 2026 | A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte st... |
| CVE-2026-35379 | LOW | 3.3 | 0.1% | Apr 22, 2026 | A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:]... |
| CVE-2026-35378 | LOW | 3.3 | 0.2% | Apr 22, 2026 | A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now