2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5442 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Represe... |
| CVE-2026-5441 | HIGH | 7.1 | 0.1% | Apr 9, 2026 | An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1... |
| CVE-2026-5440 | HIGH | 7.5 | 0.6% | Apr 9, 2026 | A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The se... |
| CVE-2026-5439 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded... |
| CVE-2026-5438 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The se... |
| CVE-2026-5437 | HIGH | 7.5 | 0.6% | Apr 9, 2026 | An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malf... |
| CVE-2026-4116 | HIGH | 7.2 | 0.4% | Apr 9, 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user t... |
| CVE-2026-4114 | MEDIUM | 6.6 | 0.6% | Apr 9, 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin ... |
| CVE-2026-4113 | HIGH | 7.2 | 0.4% | Apr 9, 2026 | An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to ... |
| CVE-2026-4112 | HIGH | 7.2 | 0.6% | Apr 9, 2026 | Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series applian... |
| CVE-2026-34757 | MEDIUM | 4.4 | 0.2% | Apr 9, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2026-34578 | HIGH | 8.2 | 0.4% | Apr 9, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector pas... |
| CVE-2026-4660 | HIGH | 7.5 | 0.6% | Apr 9, 2026 | HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operatio... |
| CVE-2026-3005 | MEDIUM | 6.4 | 0.3% | Apr 9, 2026 | The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho... |
| CVE-2026-2519 | MEDIUM | 5.3 | 0.5% | Apr 9, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation v... |
| CVE-2026-24661 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which all... |
| CVE-2026-21388 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which all... |
| CVE-2026-4901 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker... |
| CVE-2026-34538 | MEDIUM | 6.5 | 0.7% | Apr 9, 2026 | Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have ... |
| CVE-2026-34185 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in pla... |
| CVE-2026-34184 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all file... |
| CVE-2026-34179 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate th... |
| CVE-2026-34178 | CRITICAL | 9.1 | 0.4% | Apr 9, 2026 | In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supp... |
| CVE-2026-34177 | CRITICAL | 9.1 | 0.4% | Apr 9, 2026 | Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limit... |
| CVE-2026-5854 | CRITICAL | 9.8 | 17.5% | Apr 9, 2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEas... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now