2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41459 | MEDIUM | 6.9 | 0.8% | Apr 22, 2026 | Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthentica... |
| CVE-2026-28950 | MEDIUM | 6.2 | 2.9% | Apr 22, 2026 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.... |
| CVE-2026-6515 | MEDIUM | 5.4 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2026-5377 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed ... |
| CVE-2026-5262 | MEDIUM | 6.1 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, a... |
| CVE-2026-35380 | MEDIUM | 5.5 | 0.2% | Apr 22, 2026 | A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte st... |
| CVE-2026-35376 | MEDIUM | 5.8 | 0.1% | Apr 22, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutils during recursive o... |
| CVE-2026-35374 | MEDIUM | 6.3 | 0.1% | Apr 22, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the split utility of uutils coreutils. The program attem... |
| CVE-2026-35373 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filen... |
| CVE-2026-35372 | MEDIUM | 5 | 0.1% | Apr 22, 2026 | A logic error in the ln utility of uutils coreutils allows the utility to dereference a symbolic link target even when t... |
| CVE-2026-35370 | MEDIUM | 4.4 | 0.1% | Apr 22, 2026 | The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's rea... |
| CVE-2026-35369 | MEDIUM | 5.5 | 0.1% | Apr 22, 2026 | An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send th... |
| CVE-2026-35366 | MEDIUM | 4.4 | 0.2% | Apr 22, 2026 | The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences.... |
| CVE-2026-35365 | MEDIUM | 6.6 | 0.2% | Apr 22, 2026 | The mv utility in uutils coreutils improperly handles directory trees containing symbolic links during moves across file... |
| CVE-2026-35364 | MEDIUM | 6.3 | 0.1% | Apr 22, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mv utility of uutils coreutils during cross-device ... |
| CVE-2026-35363 | MEDIUM | 5.6 | 0.2% | Apr 22, 2026 | A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the ... |
| CVE-2026-35361 | MEDIUM | 4.4 | 0.1% | Apr 22, 2026 | The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting... |
| CVE-2026-35360 | MEDIUM | 6.3 | 0.1% | Apr 22, 2026 | The touch utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during fil... |
| CVE-2026-35359 | MEDIUM | 4.7 | 0.1% | Apr 22, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability in the cp utility of uutils coreutils allows an attacker to bypass... |
| CVE-2026-35358 | MEDIUM | 5.5 | 0.2% | Apr 22, 2026 | The cp utility in uutils coreutils, when performing recursive copies (-R), incorrectly treats character and block device... |
| CVE-2026-35357 | MEDIUM | 4.7 | 0.1% | Apr 22, 2026 | The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are init... |
| CVE-2026-35356 | MEDIUM | 6.3 | 0.1% | Apr 22, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -... |
| CVE-2026-35355 | MEDIUM | 6.3 | 0.1% | Apr 22, 2026 | The install utility in uutils coreutils is vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition during f... |
| CVE-2026-35354 | MEDIUM | 4.7 | 0.1% | Apr 22, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the mv utility of uutils coreutils during cross-device m... |
| CVE-2026-35351 | MEDIUM | 4.2 | 0.1% | Apr 22, 2026 | The mv utility in uutils coreutils fails to preserve file ownership during moves across different filesystem boundaries.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now