2026 CVE Vulnerabilities
49,000 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31701 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: caiaq: take a reference on the USB device in ... |
| CVE-2026-7581 | MEDIUM | 4.3 | 0.2% | May 1, 2026 | A security vulnerability has been detected in alexta69 MeTube up to 2026.04.09. This affects the function on_prepare of ... |
| CVE-2026-7580 | MEDIUM | 5.3 | 0.2% | May 1, 2026 | A vulnerability was detected in Exiftool up to 13.53. Impacted is the function Process_mrld of the file lib/Image/ExifTo... |
| CVE-2026-3140 | MEDIUM | 4.3 | 0.2% | May 1, 2026 | The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2026-7578 | MEDIUM | 4.7 | 0.2% | May 1, 2026 | A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file... |
| CVE-2026-40201 | MEDIUM | 5.4 | 0.2% | May 1, 2026 | @diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file. |
| CVE-2026-6127 | MEDIUM | 6.4 | 0.2% | May 1, 2026 | The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data ... |
| CVE-2026-7553 | MEDIUM | 4.7 | 0.2% | May 1, 2026 | A vulnerability was found in code-projects Gym Management System 1.0. Affected by this vulnerability is an unknown funct... |
| CVE-2026-7536 | MEDIUM | 5.5 | 0.4% | May 1, 2026 | A vulnerability was determined in Open5GS up to 2.7.7. This vulnerability affects the function bsf_sess_add_by_ip_addres... |
| CVE-2026-7535 | MEDIUM | 4.3 | 0.3% | May 1, 2026 | A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_upd... |
| CVE-2026-7518 | MEDIUM | 4.3 | 0.4% | May 1, 2026 | A flaw has been found in Open5GS up to 2.7.7. This issue affects the function amf_namf_callback_handle_sdm_data_change_n... |
| CVE-2026-5404 | MEDIUM | 5.5 | 0.1% | May 1, 2026 | K12 RF5 file parser crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service |
| CVE-2026-22726 | MEDIUM | 5 | 0.2% | May 1, 2026 | Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules.... |
| CVE-2026-7510 | MEDIUM | 6.3 | 0.3% | Apr 30, 2026 | A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionali... |
| CVE-2026-7508 | MEDIUM | 6.3 | 0.2% | Apr 30, 2026 | A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/page... |
| CVE-2026-28909 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentia... |
| CVE-2026-7502 | MEDIUM | 5.4 | 0.3% | Apr 30, 2026 | A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function s... |
| CVE-2026-40686 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing character... |
| CVE-2026-3345 | MEDIUM | 6.5 | 0.4% | Apr 30, 2026 | IBM Langflow Desktop <=1.8.4 Langflow could allow a remote attacker to traverse directories on the system. An attacker c... |
| CVE-2026-1577 | MEDIUM | 6.5 | 0.3% | Apr 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2026-6539 | MEDIUM | 4.6 | 0.2% | Apr 30, 2026 | Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers... |
| CVE-2026-4502 | MEDIUM | 6.5 | 0.3% | Apr 30, 2026 | IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the s... |
| CVE-2026-41174 | MEDIUM | 6.4 | 0.3% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potent... |
| CVE-2026-40951 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with loc... |
| CVE-2026-40950 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now