2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4313 | LOW | 2.4 | 0.6% | Apr 24, 2026 | AdaptiveGRC is vulnerable to Stored XSS via text type fields across the forms. Authenticated attacker can replace the va... |
| CVE-2026-29051 | LOW | 3.3 | 0.2% | Apr 24, 2026 | melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version ... |
| CVE-2026-41357 | LOW | 3.3 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass... |
| CVE-2026-4512 | LOW | 3.5 | 0.2% | Apr 23, 2026 | The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputt... |
| CVE-2026-41988 | LOW | 2.5 | 0.1% | Apr 23, 2026 | uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6.... |
| CVE-2026-3254 | LOW | 3.5 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain condi... |
| CVE-2026-35381 | LOW | 3.3 | 0.1% | Apr 22, 2026 | A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when usin... |
| CVE-2026-35379 | LOW | 3.3 | 0.1% | Apr 22, 2026 | A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:]... |
| CVE-2026-35378 | LOW | 3.3 | 0.2% | Apr 22, 2026 | A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during... |
| CVE-2026-35377 | LOW | 3.3 | 0.1% | Apr 22, 2026 | A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when uti... |
| CVE-2026-35375 | LOW | 3.3 | 0.1% | Apr 22, 2026 | A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-... |
| CVE-2026-35371 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effect... |
| CVE-2026-35367 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted... |
| CVE-2026-35362 | LOW | 3.6 | 0.2% | Apr 22, 2026 | The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) s... |
| CVE-2026-35353 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory wit... |
| CVE-2026-35346 | LOW | 3.3 | 0.2% | Apr 22, 2026 | The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. Th... |
| CVE-2026-35344 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result... |
| CVE-2026-35343 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is speci... |
| CVE-2026-35342 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp,... |
| CVE-2026-6842 | LOW | 2.5 | 0.1% | Apr 22, 2026 | A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directo... |
| CVE-2026-22746 | LOW | 3.7 | 0.2% | Apr 22, 2026 | Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or ... |
| CVE-2026-6408 | LOW | 2.7 | 0.2% | Apr 22, 2026 | Tanium addressed an information disclosure vulnerability in Tanium Server. |
| CVE-2026-6392 | LOW | 2.7 | 0.2% | Apr 22, 2026 | Tanium addressed an information disclosure vulnerability in Threat Response. |
| CVE-2026-3307 | LOW | 2.7 | 0.3% | Apr 21, 2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin acc... |
| CVE-2026-35250 | LOW | 2.3 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now