2026 CVE Vulnerabilities
65,972 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21376 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor... |
| CVE-2026-21375 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
| CVE-2026-21374 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio... |
| CVE-2026-21373 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
| CVE-2026-21372 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. |
| CVE-2026-21371 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when retrieving output buffer with insufficient size validation. |
| CVE-2026-21367 | HIGH | 7.5 | 0.2% | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. |
| CVE-2026-5664 | — | — | — | Apr 6, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-30078. Reason: This candidate is a ... |
| CVE-2026-5663 | CRITICAL | 9.8 | 1.7% | Apr 6, 2026 | A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEn... |
| CVE-2026-5661 | MEDIUM | 5.5 | 0.4% | Apr 6, 2026 | A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handle... |
| CVE-2026-34897 | MEDIUM | 6.5 | 0.2% | Apr 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi... |
| CVE-2026-34885 | HIGH | 8.5 | 1.7% | Apr 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi... |
| CVE-2026-33540 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mod... |
| CVE-2026-33510 | HIGH | 8.8 | 0.2% | Apr 6, 2026 | Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been disco... |
| CVE-2026-33406 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-33404 | MEDIUM | 6.1 | 0.1% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-33403 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-32602 | MEDIUM | 4.2 | 0.1% | Apr 6, 2026 | Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnera... |
| CVE-2026-31153 | MEDIUM | 5.4 | 0.1% | Apr 6, 2026 | A stored cross-site scripting (XSS) vulnerability in Bynder before 12 January 2026 allows attackers to execute arbitrary... |
| CVE-2026-31151 | CRITICAL | 9.8 | 0.4% | Apr 6, 2026 | An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the appl... |
| CVE-2026-31150 | MEDIUM | 4.3 | 0.2% | Apr 6, 2026 | Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to... |
| CVE-2026-31067 | MEDIUM | 6.8 | 0.5% | Apr 6, 2026 | A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7... |
| CVE-2026-31066 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of th... |
| CVE-2026-31065 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formC... |
| CVE-2026-31063 | MEDIUM | 4.5 | 0.2% | Apr 6, 2026 | UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the form... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now