2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6182 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is ... |
| CVE-2026-36945 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a... |
| CVE-2026-36944 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerale to SQL injection in the file/rsms/adm... |
| CVE-2026-36943 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a... |
| CVE-2026-36942 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL injection in the file /orms/admin/activities/ma... |
| CVE-2026-36941 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Resort Management System v1.0 is vulnerable to SQL Injection in the file /orms/admin/rooms/manage_... |
| CVE-2026-33858 | HIGH | 8.8 | 0.6% | Apr 13, 2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t... |
| CVE-2026-31283 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | In Totara LMS v19.1.5 and before, the forgot password API does not implement rate limiting for the target email address.... |
| CVE-2026-31282 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Control. The login page code can be manipulated to revea... |
| CVE-2026-31281 | HIGH | 8 | 0.3% | Apr 13, 2026 | Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a... |
| CVE-2026-30999 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Servi... |
| CVE-2026-30998 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows att... |
| CVE-2026-30997 | HIGH | 7.5 | 0.3% | Apr 13, 2026 | An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cau... |
| CVE-2026-29628 | MEDIUM | 6.2 | 0.2% | Apr 13, 2026 | A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause... |
| CVE-2026-1462 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow S... |
| CVE-2026-36947 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL Injection in the file /rsms/a... |
| CVE-2026-36946 | LOW | 2.7 | 0.3% | Apr 13, 2026 | Sourcecodester Computer and Mobile Repair Shop Management System v1.0 is vulnerable to SQL injection in the file /rsms/a... |
| CVE-2026-31428 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding... |
| CVE-2026-31427 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitializ... |
| CVE-2026-31426 | HIGH | 7 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acp... |
| CVE-2026-31425 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration before IB connect... |
| CVE-2026-31424 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_che... |
| CVE-2026-31423 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min... |
| CVE-2026-31422 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference o... |
| CVE-2026-31421 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL pointer dereference on ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now