2026 CVE Vulnerabilities
64,982 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35352 | HIGH | 7 | 0.1% | Apr 22, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility cre... |
| CVE-2026-35351 | MEDIUM | 4.2 | 0.1% | Apr 22, 2026 | The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries.... |
| CVE-2026-35350 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | The cp utility in uutils coreutils fails to properly handle setuid and setgid bits when ownership preservation fails. Wh... |
| CVE-2026-35349 | HIGH | 7.7 | 0.2% | Apr 22, 2026 | A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementat... |
| CVE-2026-35348 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | The sort utility in uutils coreutils is vulnerable to a process panic when using the --files0-from option with inputs co... |
| CVE-2026-35347 | MEDIUM | 4.4 | 0.1% | Apr 22, 2026 | The comm utility in uutils coreutils incorrectly consumes data from non-regular file inputs before performing comparison... |
| CVE-2026-35346 | LOW | 3.3 | 0.2% | Apr 22, 2026 | The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. Th... |
| CVE-2026-35345 | MEDIUM | 5.3 | 0.1% | Apr 22, 2026 | A vulnerability in the tail utility of uutils coreutils allows for the exfiltration of sensitive file contents when usin... |
| CVE-2026-35344 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result... |
| CVE-2026-35343 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is speci... |
| CVE-2026-35342 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp,... |
| CVE-2026-35341 | HIGH | 7.1 | 0.2% | Apr 22, 2026 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. Wh... |
| CVE-2026-35340 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | A flaw in the ChownExecutor used by uutils coreutils chown and chgrp causes the utilities to return an incorrect exit co... |
| CVE-2026-35339 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple... |
| CVE-2026-35338 | HIGH | 7.3 | 0.2% | Apr 22, 2026 | A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. Th... |
| CVE-2026-32885 | CRITICAL | 9.1 | 0.4% | Apr 22, 2026 | DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2... |
| CVE-2026-1660 | MEDIUM | 6.5 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2026-30139 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | A reflected cross-site scripting (XSS) vulnerability in the AdvancedSearch functionality of Silverpeas Core before versi... |
| CVE-2026-35548 | HIGH | 8.5 | 0.2% | Apr 22, 2026 | An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix ... |
| CVE-2026-6862 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | A flaw was found in libefiboot, a component of efivar. The device path node parser in libefiboot fails to validate that ... |
| CVE-2026-6861 | HIGH | 7.1 | 0.1% | Apr 22, 2026 | A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially craf... |
| CVE-2026-6859 | HIGH | 8.8 | 0.4% | Apr 22, 2026 | A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from... |
| CVE-2026-6356 | CRITICAL | 9.6 | 0.3% | Apr 22, 2026 | A vulnerability in the web application allows standard users to escalate their privileges to those of a super administra... |
| CVE-2026-6355 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across differen... |
| CVE-2026-5750 | HIGH | 7.6 | 0.2% | Apr 22, 2026 | An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now