2026 CVE Vulnerabilities
48,948 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35233 | MEDIUM | 4.4 | 0.1% | May 1, 2026 | An unprivileged attacker can craft a user-space process with a malicious ELF binary containing an out-of-range sh_link f... |
| CVE-2026-26461 | MEDIUM | 6.5 | 0.8% | May 1, 2026 | A Command Injection vulnerability in the web management interface in Aver PTC320UV2 0.1.0000.65 allows an unauthenticate... |
| CVE-2026-21996 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an intege... |
| CVE-2026-7587 | MEDIUM | 4.3 | 0.3% | May 1, 2026 | A vulnerability has been found in Open5GS up to 2.7.7. This vulnerability affects the function amf_nsmf_pdusession_handl... |
| CVE-2026-7586 | MEDIUM | 4.3 | 0.3% | May 1, 2026 | A weakness has been identified in Open5GS up to 2.7.7. Affected is the function ogs_id_get_value of the file /src/amf/nu... |
| CVE-2026-7585 | MEDIUM | 4.3 | 0.3% | May 1, 2026 | A vulnerability was determined in Open5GS up to 2.7.7. The impacted element is the function amf_nudm_sdm_handle_provisio... |
| CVE-2026-42481 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can b... |
| CVE-2026-42480 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology... |
| CVE-2026-42475 | MEDIUM | 6.5 | 0.2% | May 1, 2026 | SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHe... |
| CVE-2026-42474 | MEDIUM | 6.5 | 0.2% | May 1, 2026 | SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `data` array to the data function in BuildHe... |
| CVE-2026-37505 | MEDIUM | 4.9 | 0.2% | May 1, 2026 | SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort para... |
| CVE-2026-37503 | MEDIUM | 4.8 | 0.2% | May 1, 2026 | Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade u... |
| CVE-2026-23866 | MEDIUM | 4.3 | 0.5% | May 1, 2026 | Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and ... |
| CVE-2026-23863 | MEDIUM | 6.5 | 0.5% | May 1, 2026 | An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously f... |
| CVE-2026-7583 | MEDIUM | 4.3 | 0.3% | May 1, 2026 | A flaw has been found in Open5GS up to 2.7.7. This issue affects the function bsf_sess_find_by_ipv6prefix of the file /s... |
| CVE-2026-43505 | MEDIUM | 6.5 | 0.2% | May 1, 2026 | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Be... |
| CVE-2026-43504 | MEDIUM | 6.5 | 0.3% | May 1, 2026 | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Be... |
| CVE-2026-43054 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: tcm_loop: Drain commands in target_re... |
| CVE-2026-43053 | MEDIUM | 4.7 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfs: close crash window in attr dabtree inactivatio... |
| CVE-2026-43046 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: reject root items with drop_progress and zer... |
| CVE-2026-43045 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: mshv: Fix error handling in mshv_region_pin The cu... |
| CVE-2026-43043 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: af-alg - fix NULL pointer dereference in sc... |
| CVE-2026-43041 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: replace qrtr_tx_flow radix_tree with xar... |
| CVE-2026-43036 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: use skb_header_pointer() for TCPv4 GSO frag_of... |
| CVE-2026-43035 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: sched: cls_api: fix tc_chain_fill_node to init... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now