2026 CVE Vulnerabilities
65,368 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34477 | MEDIUM | 5.9 | 0.4% | Apr 10, 2026 | The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna... |
| CVE-2026-29043 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can t... |
| CVE-2026-29002 | HIGH | 8.6 | 0.4% | Apr 10, 2026 | CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin ... |
| CVE-2026-23781 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded... |
| CVE-2026-36236 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password p... |
| CVE-2026-36235 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System... |
| CVE-2026-36234 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' ... |
| CVE-2026-36233 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollme... |
| CVE-2026-36232 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment Syst... |
| CVE-2026-31262 | MEDIUM | 6.1 | 0.2% | Apr 10, 2026 | Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai... |
| CVE-2026-29861 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at l... |
| CVE-2026-23782 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated us... |
| CVE-2026-23780 | HIGH | 8.8 | 0.4% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug... |
| CVE-2026-6069 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker... |
| CVE-2026-6068 | CRITICAL | 9.6 | 0.4% | Apr 10, 2026 | NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed mem... |
| CVE-2026-6067 | MEDIUM | 5.5 | 0.4% | Apr 10, 2026 | A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_... |
| CVE-2026-40217 | HIGH | 8.8 | 6.5% | Apr 10, 2026 | LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t... |
| CVE-2026-33092 | HIGH | 7.8 | 0.2% | Apr 10, 2026 | Local privilege escalation due to improper handling of environment variables. The following products are affected: Acron... |
| CVE-2026-5774 | MEDIUM | 6.4 | 0.2% | Apr 10, 2026 | Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow a... |
| CVE-2026-5412 | MEDIUM | 6.5 | 0.4% | Apr 10, 2026 | In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated us... |
| CVE-2026-5777 | HIGH | 8.7 | 0.3% | Apr 10, 2026 | This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service ov... |
| CVE-2026-39304 | HIGH | 7.5 | 0.9% | Apr 10, 2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. A... |
| CVE-2026-31412 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer ... |
| CVE-2026-6057 | CRITICAL | 9.8 | 0.9% | Apr 10, 2026 | FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remot... |
| CVE-2026-4162 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. Th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now