2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34486 | HIGH | 7.5 | 98.6% | Apr 9, 2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypas... |
| CVE-2026-34483 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue ... |
| CVE-2026-32990 | MEDIUM | 5.3 | 0.3% | Apr 9, 2026 | Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects... |
| CVE-2026-29923 | HIGH | 7.8 | 0.1% | Apr 9, 2026 | The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a... |
| CVE-2026-29146 | HIGH | 7.5 | 6.3% | Apr 9, 2026 | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apach... |
| CVE-2026-29145 | CRITICAL | 9.1 | 0.7% | Apr 9, 2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apac... |
| CVE-2026-29129 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from... |
| CVE-2026-25854 | MEDIUM | 6.1 | 0.5% | Apr 9, 2026 | Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDraini... |
| CVE-2026-24880 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via inva... |
| CVE-2026-39912 | CRITICAL | 9.1 | 0.6% | Apr 9, 2026 | V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWi... |
| CVE-2026-35556 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve cre... |
| CVE-2026-35195 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco... |
| CVE-2026-35186 | HIGH | 7.5 | 0.2% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backe... |
| CVE-2026-34988 | MEDIUM | 6.3 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of it... |
| CVE-2026-34987 | CRITICAL | 9.9 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseli... |
| CVE-2026-34983 | MEDIUM | 5 | 0.1% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free... |
| CVE-2026-34971 | CRITICAL | 9 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilatio... |
| CVE-2026-34946 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta... |
| CVE-2026-34945 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta... |
| CVE-2026-34944 | MEDIUM | 5.7 | 0.2% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabl... |
| CVE-2026-34943 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic w... |
| CVE-2026-34942 | MEDIUM | 6.5 | 0.4% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco... |
| CVE-2026-34941 | HIGH | 8.1 | 0.4% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability wh... |
| CVE-2026-31170 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-28205 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now