2026 CVE Vulnerabilities
50,562 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40223 | MEDIUM | 5.5 | 0.1% | Apr 10, 2026 | In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi... |
| CVE-2026-40023 | MEDIUM | 5.3 | 0.5% | Apr 10, 2026 | Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions... |
| CVE-2026-40021 | MEDIUM | 5.3 | 0.8% | Apr 10, 2026 | Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLa... |
| CVE-2026-35594 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (Get... |
| CVE-2026-34477 | MEDIUM | 5.9 | 0.4% | Apr 10, 2026 | The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna... |
| CVE-2026-29043 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can t... |
| CVE-2026-31262 | MEDIUM | 6.1 | 0.2% | Apr 10, 2026 | Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai... |
| CVE-2026-6067 | MEDIUM | 5.5 | 0.4% | Apr 10, 2026 | A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_... |
| CVE-2026-5774 | MEDIUM | 6.4 | 0.2% | Apr 10, 2026 | Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow a... |
| CVE-2026-5412 | MEDIUM | 6.5 | 0.4% | Apr 10, 2026 | In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated us... |
| CVE-2026-31412 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer ... |
| CVE-2026-6042 | MEDIUM | 4.8 | 0.2% | Apr 10, 2026 | A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/icon... |
| CVE-2026-33457 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated ... |
| CVE-2026-33455 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livest... |
| CVE-2026-6035 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unkno... |
| CVE-2026-6034 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-6033 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedet... |
| CVE-2026-6032 | MEDIUM | 4.3 | 0.4% | Apr 10, 2026 | A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /chec... |
| CVE-2026-40212 | MEDIUM | 5.4 | 0.2% | Apr 10, 2026 | OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console... |
| CVE-2026-6030 | MEDIUM | 6.3 | 0.3% | Apr 10, 2026 | A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of... |
| CVE-2026-4432 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist ownership in the save_t... |
| CVE-2026-4482 | MEDIUM | 5.5 | 0.1% | Apr 10, 2026 | The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windo... |
| CVE-2026-6010 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknow... |
| CVE-2026-6007 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the fi... |
| CVE-2026-6006 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now