2026 CVE Vulnerabilities
50,404 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6190 | MEDIUM | 6.3 | 0.2% | Apr 13, 2026 | A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown functio... |
| CVE-2026-39940 | MEDIUM | 5.3 | 0.3% | Apr 13, 2026 | ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCR... |
| CVE-2026-33555 | MEDIUM | 5.8 | 0.3% | Apr 13, 2026 | An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches ... |
| CVE-2026-30812 | MEDIUM | 5.4 | 0.2% | Apr 13, 2026 | Improper Neutralization of Input During Web Page Generation vulnerability allows Stored Cross-Site Scripting via event c... |
| CVE-2026-30811 | MEDIUM | 6.5 | 0.3% | Apr 13, 2026 | Missing Authorization vulnerability allows Exposure of Sensitive Information via configuration endpoint. This issue affe... |
| CVE-2026-29628 | MEDIUM | 6.2 | 0.2% | Apr 13, 2026 | A stack overflow in the experimental/tinyobj_loader_opt.h file of tinyobjloader commit d56555b allows attackers to cause... |
| CVE-2026-31428 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: fix uninitialized padding... |
| CVE-2026-31427 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: fix use of uninitializ... |
| CVE-2026-31425 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: rds: ib: reject FRMR registration before IB connect... |
| CVE-2026-31424 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: restrict xt_check_match/xt_che... |
| CVE-2026-31423 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min... |
| CVE-2026-31422 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_flow: fix NULL pointer dereference o... |
| CVE-2026-31421 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_fw: fix NULL pointer dereference on ... |
| CVE-2026-31420 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: bridge: mrp: reject zero test interval to avoid OOM... |
| CVE-2026-31418 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: drop logically empty buckets in m... |
| CVE-2026-31416 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: account for netlink heade... |
| CVE-2026-31415 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid overflows in ip6_datagram_send_ctl() Y... |
| CVE-2026-2728 | MEDIUM | 4.8 | 0.2% | Apr 13, 2026 | LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig pa... |
| CVE-2026-35565 | MEDIUM | 5.4 | 0.5% | Apr 13, 2026 | Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata in Apache Storm UI Versions Affected: before 2.8.6... |
| CVE-2026-0232 | MEDIUM | 4.4 | 0.2% | Apr 13, 2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows admin... |
| CVE-2026-34866 | MEDIUM | 5.1 | 0.1% | Apr 13, 2026 | Out-of-bounds write vulnerability in the WEB module.Impact: Successful exploitation of this vulnerability will affect av... |
| CVE-2026-21013 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive in... |
| CVE-2026-21011 | MEDIUM | 6.8 | 0.1% | Apr 13, 2026 | Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attacker... |
| CVE-2026-21009 | MEDIUM | 6.8 | 0.2% | Apr 13, 2026 | Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass ... |
| CVE-2026-21008 | MEDIUM | 6.5 | 0.2% | Apr 13, 2026 | Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitiv... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now