2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7024 | MEDIUM | 5.4 | 0.4% | Apr 26, 2026 | A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unk... |
| CVE-2026-7018 | MEDIUM | 5.6 | 0.3% | Apr 26, 2026 | A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected elemen... |
| CVE-2026-42255 | MEDIUM | 6.5 | 0.2% | Apr 26, 2026 | Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation. |
| CVE-2026-42254 | MEDIUM | 4 | 0.2% | Apr 26, 2026 | Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associat... |
| CVE-2026-6994 | MEDIUM | 6.3 | 0.2% | Apr 25, 2026 | A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/... |
| CVE-2026-6993 | MEDIUM | 5.5 | 0.3% | Apr 25, 2026 | A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file tra... |
| CVE-2026-6991 | MEDIUM | 6.3 | 0.2% | Apr 25, 2026 | A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file pa... |
| CVE-2026-6984 | MEDIUM | 4.7 | 0.3% | Apr 25, 2026 | A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of th... |
| CVE-2026-6983 | MEDIUM | 4.7 | 0.3% | Apr 25, 2026 | A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file... |
| CVE-2026-6982 | MEDIUM | 6.3 | 0.2% | Apr 25, 2026 | A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknow... |
| CVE-2026-6981 | MEDIUM | 6.3 | 0.3% | Apr 25, 2026 | A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected i... |
| CVE-2026-6979 | MEDIUM | 6.3 | 0.3% | Apr 25, 2026 | A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.con... |
| CVE-2026-6978 | MEDIUM | 4.7 | 0.3% | Apr 25, 2026 | A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of th... |
| CVE-2026-31684 | MEDIUM | 5.5 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: sched: act_csum: validate nested VLAN headers ... |
| CVE-2026-31681 | MEDIUM | 5.5 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in... |
| CVE-2026-31677 | MEDIUM | 5.5 | 0.1% | Apr 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive ... |
| CVE-2026-41481 | MEDIUM | 6.5 | 0.3% | Apr 24, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTM... |
| CVE-2026-41472 | MEDIUM | 6.1 | 0.5% | Apr 24, 2026 | CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where... |
| CVE-2026-6968 | MEDIUM | 6.5 | 0.5% | Apr 24, 2026 | Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated si... |
| CVE-2026-6967 | MEDIUM | 6.5 | 0.2% | Apr 24, 2026 | Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 ... |
| CVE-2026-6966 | MEDIUM | 6.5 | 0.3% | Apr 24, 2026 | Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v... |
| CVE-2026-41427 | MEDIUM | 6.5 | 0.2% | Apr 24, 2026 | Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option d... |
| CVE-2026-41426 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered e... |
| CVE-2026-41425 | MEDIUM | 5.4 | 0.1% | Apr 24, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection ... |
| CVE-2026-41244 | MEDIUM | 4.7 | 0.1% | Apr 24, 2026 | Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the Ci... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now