2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40224 | HIGH | 7.3 | 0.1% | Apr 10, 2026 | In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach ... |
| CVE-2026-40223 | MEDIUM | 5.5 | 0.1% | Apr 10, 2026 | In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi... |
| CVE-2026-40023 | MEDIUM | 5.3 | 0.5% | Apr 10, 2026 | Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions... |
| CVE-2026-40021 | MEDIUM | 5.3 | 0.8% | Apr 10, 2026 | Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLa... |
| CVE-2026-35594 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (Get... |
| CVE-2026-34727 | CRITICAL | 9.1 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the OIDC callback handler issues a full ... |
| CVE-2026-34481 | HIGH | 7.5 | 0.6% | Apr 10, 2026 | Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions u... |
| CVE-2026-34480 | HIGH | 7.5 | 0.9% | Apr 10, 2026 | Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to an... |
| CVE-2026-34479 | HIGH | 7.5 | 0.5% | Apr 10, 2026 | The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standa... |
| CVE-2026-34478 | HIGH | 7.5 | 0.8% | Apr 10, 2026 | Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions ... |
| CVE-2026-34477 | MEDIUM | 5.9 | 0.4% | Apr 10, 2026 | The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna... |
| CVE-2026-29043 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can t... |
| CVE-2026-29002 | HIGH | 8.6 | 0.4% | Apr 10, 2026 | CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin ... |
| CVE-2026-23781 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded... |
| CVE-2026-36236 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password p... |
| CVE-2026-36235 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System... |
| CVE-2026-36234 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' ... |
| CVE-2026-36233 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollme... |
| CVE-2026-36232 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment Syst... |
| CVE-2026-31262 | MEDIUM | 6.1 | 0.2% | Apr 10, 2026 | Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai... |
| CVE-2026-29861 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at l... |
| CVE-2026-23782 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated us... |
| CVE-2026-23780 | HIGH | 8.8 | 0.4% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug... |
| CVE-2026-6069 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker... |
| CVE-2026-6068 | CRITICAL | 9.6 | 0.4% | Apr 10, 2026 | NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed mem... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now