2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5493 | HIGH | 7.8 | 0.3% | Apr 11, 2026 | Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerab... |
| CVE-2026-5059 | CRITICAL | 9.8 | 1.9% | Apr 11, 2026 | aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers... |
| CVE-2026-5058 | CRITICAL | 9.8 | 1.8% | Apr 11, 2026 | aws-mcp-server Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to exec... |
| CVE-2026-5055 | HIGH | 7.8 | 0.2% | Apr 11, 2026 | NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local att... |
| CVE-2026-5054 | HIGH | 7.8 | 0.2% | Apr 11, 2026 | NoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attack... |
| CVE-2026-5053 | HIGH | 7.1 | 0.1% | Apr 11, 2026 | NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability allows local attackers... |
| CVE-2026-4158 | HIGH | 7.3 | 0.2% | Apr 11, 2026 | KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerab... |
| CVE-2026-4157 | HIGH | 7.5 | 0.9% | Apr 11, 2026 | ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows ne... |
| CVE-2026-4156 | HIGH | 7.5 | 0.4% | Apr 11, 2026 | ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a... |
| CVE-2026-4155 | HIGH | 7.5 | 0.6% | Apr 11, 2026 | ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulne... |
| CVE-2026-4154 | HIGH | 7.8 | 0.6% | Apr 11, 2026 | GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t... |
| CVE-2026-4153 | HIGH | 7.8 | 0.7% | Apr 11, 2026 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-4152 | HIGH | 7.8 | 0.7% | Apr 11, 2026 | GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-4151 | HIGH | 7.8 | 0.7% | Apr 11, 2026 | GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t... |
| CVE-2026-4150 | HIGH | 7.8 | 0.8% | Apr 11, 2026 | GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t... |
| CVE-2026-4149 | CRITICAL | 9.8 | 1.0% | Apr 11, 2026 | Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote at... |
| CVE-2026-40354 | MEDIUM | 6.3 | 0.1% | Apr 11, 2026 | Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host c... |
| CVE-2026-3691 | MEDIUM | 5.3 | 0.5% | Apr 11, 2026 | OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclo... |
| CVE-2026-3690 | HIGH | 7.4 | 0.7% | Apr 11, 2026 | OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication... |
| CVE-2026-3689 | MEDIUM | 6.5 | 0.9% | Apr 11, 2026 | OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl... |
| CVE-2026-40199 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pa... |
| CVE-2026-40198 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_... |
| CVE-2026-33119 | MEDIUM | 5.4 | 0.3% | Apr 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-33118 | MEDIUM | 4.3 | 0.6% | Apr 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-5724 | MEDIUM | 6.3 | 0.5% | Apr 10, 2026 | The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now