2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40450 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and... |
| CVE-2026-40449 | MEDIUM | 6.6 | 0.1% | Apr 22, 2026 | Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in S... |
| CVE-2026-40448 | MEDIUM | 5.3 | 0.1% | Apr 22, 2026 | Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large ... |
| CVE-2026-22754 | HIGH | 7.5 | 0.3% | Apr 22, 2026 | Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=... |
| CVE-2026-22753 | HIGH | 7.5 | 0.2% | Apr 22, 2026 | Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMat... |
| CVE-2026-22748 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusRea... |
| CVE-2026-22747 | HIGH | 8.1 | 0.3% | Apr 22, 2026 | Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509... |
| CVE-2026-22746 | LOW | 3.7 | 0.2% | Apr 22, 2026 | Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or ... |
| CVE-2026-40451 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | DeepL Chrome browser extension versions from v1.22.0 to v.1.23.0 contain a cross-site scripting vulnerability, which all... |
| CVE-2026-6835 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | The a+HCM developed by aEnrich has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to ... |
| CVE-2026-6834 | HIGH | 7.1 | 0.3% | Apr 22, 2026 | The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arb... |
| CVE-2026-6833 | HIGH | 7.1 | 0.3% | Apr 22, 2026 | The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbi... |
| CVE-2026-6416 | MEDIUM | 4.9 | 0.3% | Apr 22, 2026 | Tanium addressed an uncontrolled resource consumption vulnerability in Interact. |
| CVE-2026-6408 | LOW | 2.7 | 0.2% | Apr 22, 2026 | Tanium addressed an information disclosure vulnerability in Tanium Server. |
| CVE-2026-6392 | LOW | 2.7 | 0.2% | Apr 22, 2026 | Tanium addressed an information disclosure vulnerability in Threat Response. |
| CVE-2026-6386 | MEDIUM | 6.2 | 0.2% | Apr 22, 2026 | In order to apply a particular protection key to an address range, the kernel must update the corresponding page table e... |
| CVE-2026-5398 | HIGH | 8.4 | 0.2% | Apr 22, 2026 | The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal ... |
| CVE-2026-41458 | HIGH | 8.2 | 0.4% | Apr 22, 2026 | OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows u... |
| CVE-2026-41457 | MEDIUM | 6.9 | 0.3% | Apr 22, 2026 | OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that a... |
| CVE-2026-41146 | HIGH | 8.7 | 0.3% | Apr 22, 2026 | facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_jso... |
| CVE-2026-41145 | HIGH | 8.2 | 0.3% | Apr 22, 2026 | MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04... |
| CVE-2026-40344 | HIGH | 8.2 | 0.4% | Apr 22, 2026 | MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04... |
| CVE-2026-41304 | CRITICAL | 9.8 | 2.2% | Apr 22, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the Clo... |
| CVE-2026-41144 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applicati... |
| CVE-2026-41136 | MEDIUM | 5.3 | 0.3% | Apr 22, 2026 | free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now