2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41418 | MEDIUM | 5.3 | 0.2% | Apr 24, 2026 | 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumerat... |
| CVE-2026-42042 | MEDIUM | 5.4 | 0.2% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF t... |
| CVE-2026-42041 | MEDIUM | 6.5 | 0.6% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulne... |
| CVE-2026-42037 | MEDIUM | 5.3 | 0.2% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart construc... |
| CVE-2026-42036 | MEDIUM | 5.3 | 0.4% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream... |
| CVE-2026-42034 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies,... |
| CVE-2026-41898 | MEDIUM | 5.3 | 0.4% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampo... |
| CVE-2026-41322 | MEDIUM | 5.3 | 0.2% | Apr 24, 2026 | @astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resource... |
| CVE-2026-41411 | MEDIUM | 6.6 | 0.5% | Apr 24, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's ta... |
| CVE-2026-41079 | MEDIUM | 5.4 | 0.4% | Apr 24, 2026 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a ... |
| CVE-2026-41067 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a... |
| CVE-2026-30368 | MEDIUM | 5.4 | 0.3% | Apr 24, 2026 | A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersona... |
| CVE-2026-42095 | MEDIUM | 4 | 0.2% | Apr 24, 2026 | bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL. |
| CVE-2026-31672 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lifetime USB drivers b... |
| CVE-2026-31671 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_report() struct ... |
| CVE-2026-31670 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill ev... |
| CVE-2026-31664 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() ... |
| CVE-2026-31661 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: Fix dma_free_coherent() size dma_a... |
| CVE-2026-31660 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: allocate rx skb before consuming bytes ... |
| CVE-2026-31658 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: altera-tse: fix skb leak on DMA mapping error ... |
| CVE-2026-31655 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock ... |
| CVE-2026-31654 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/vma: fix memory leak in __mmap_region() commit ... |
| CVE-2026-31653 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs: dealloc repeat_call_control if damo... |
| CVE-2026-31651 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix NULL-deref on disconnect Make sur... |
| CVE-2026-31647 | MEDIUM | 5.5 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: idpf: fix PREEMPT_RT raw/bh spinlock nesting for as... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now