2026 CVE Vulnerabilities
49,581 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40977 | MEDIUM | 6.7 | 0.1% | Apr 28, 2026 | When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file'... |
| CVE-2026-7183 | MEDIUM | 5.5 | 0.4% | Apr 27, 2026 | A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMess... |
| CVE-2026-7179 | MEDIUM | 5.3 | 0.2% | Apr 27, 2026 | A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_nul... |
| CVE-2026-5362 | MEDIUM | 5.4 | 0.2% | Apr 27, 2026 | An authenticated attacker with permission to edit document content can store crafted HTML/JavaScript in a Document embed... |
| CVE-2026-29971 | MEDIUM | 6.1 | 0.3% | Apr 27, 2026 | A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. U... |
| CVE-2026-7150 | MEDIUM | 6.3 | 0.2% | Apr 27, 2026 | A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the ... |
| CVE-2026-7148 | MEDIUM | 6.3 | 0.2% | Apr 27, 2026 | A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Execut... |
| CVE-2026-40970 | MEDIUM | 6.8 | 0.1% | Apr 27, 2026 | When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verificat... |
| CVE-2026-35902 | MEDIUM | 6.2 | 0.2% | Apr 27, 2026 | The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication att... |
| CVE-2026-35901 | MEDIUM | 4.4 | 0.2% | Apr 27, 2026 | A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attac... |
| CVE-2026-7145 | MEDIUM | 5.4 | 0.2% | Apr 27, 2026 | A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/C... |
| CVE-2026-7144 | MEDIUM | 4.3 | 0.2% | Apr 27, 2026 | A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown functi... |
| CVE-2026-7143 | MEDIUM | 6.3 | 0.2% | Apr 27, 2026 | A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown funct... |
| CVE-2026-31691 | MEDIUM | 5.5 | 0.1% | Apr 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: igb: remove napi_synchronize() in igb_down() When ... |
| CVE-2026-31689 | MEDIUM | 5.5 | 0.1% | Apr 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc()... |
| CVE-2026-31687 | MEDIUM | 5.5 | 0.1% | Apr 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Comm... |
| CVE-2026-7142 | MEDIUM | 6.3 | 0.2% | Apr 27, 2026 | A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the f... |
| CVE-2026-7141 | MEDIUM | 5.6 | 0.3% | Apr 27, 2026 | A vulnerability was found in vLLM up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v... |
| CVE-2026-38936 | MEDIUM | 6.1 | 0.2% | Apr 27, 2026 | A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php v... |
| CVE-2026-38935 | MEDIUM | 6.1 | 0.2% | Apr 27, 2026 | A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the do... |
| CVE-2026-30462 | MEDIUM | 4.3 | 0.5% | Apr 27, 2026 | A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a dire... |
| CVE-2026-30346 | MEDIUM | 4.3 | 0.3% | Apr 27, 2026 | An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to ... |
| CVE-2026-7135 | MEDIUM | 5.3 | 0.1% | Apr 27, 2026 | A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is ... |
| CVE-2026-7134 | MEDIUM | 4.7 | 0.2% | Apr 27, 2026 | A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of th... |
| CVE-2026-41467 | MEDIUM | 5.4 | 0.2% | Apr 27, 2026 | ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionali... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now