2026 CVE Vulnerabilities
65,813 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5661 | MEDIUM | 5.5 | 0.4% | Apr 6, 2026 | A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handle... |
| CVE-2026-34897 | MEDIUM | 6.5 | 0.2% | Apr 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi... |
| CVE-2026-34885 | HIGH | 8.5 | 1.7% | Apr 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi... |
| CVE-2026-33540 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mod... |
| CVE-2026-33510 | HIGH | 8.8 | 0.2% | Apr 6, 2026 | Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been disco... |
| CVE-2026-33406 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-33404 | MEDIUM | 6.1 | 0.1% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-33403 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-32602 | MEDIUM | 4.2 | 0.1% | Apr 6, 2026 | Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnera... |
| CVE-2026-31153 | MEDIUM | 5.4 | 0.1% | Apr 6, 2026 | A stored cross-site scripting (XSS) vulnerability in Bynder before 12 January 2026 allows attackers to execute arbitrary... |
| CVE-2026-31151 | CRITICAL | 9.8 | 0.4% | Apr 6, 2026 | An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the appl... |
| CVE-2026-31150 | MEDIUM | 4.3 | 0.2% | Apr 6, 2026 | Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to... |
| CVE-2026-31067 | MEDIUM | 6.8 | 0.5% | Apr 6, 2026 | A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7... |
| CVE-2026-31066 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of th... |
| CVE-2026-31065 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formC... |
| CVE-2026-31063 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the form... |
| CVE-2026-31062 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtp... |
| CVE-2026-31061 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the ... |
| CVE-2026-31060 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the form... |
| CVE-2026-31059 | CRITICAL | 9.8 | 0.9% | Apr 6, 2026 | A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-18... |
| CVE-2026-31058 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of ... |
| CVE-2026-31053 | MEDIUM | 6.2 | 0.1% | Apr 6, 2026 | A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing m... |
| CVE-2026-29047 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user... |
| CVE-2026-26263 | CRITICAL | 9.8 | 8.7% | Apr 6, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based bli... |
| CVE-2026-26027 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now