2026 CVE Vulnerabilities
50,629 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35599 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function use... |
| CVE-2026-35598 | MEDIUM | 4.3 | 0.2% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV GetResource and GetResourcesB... |
| CVE-2026-35596 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the hasAccessToLabel function contains a... |
| CVE-2026-22560 | MEDIUM | 5.3 | 0.3% | Apr 10, 2026 | An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by... |
| CVE-2026-40227 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | In systemd 260 before 261, a local unprivileged user can trigger an assert via an IPC API call with an array or map that... |
| CVE-2026-40226 | MEDIUM | 6.4 | 0.1% | Apr 10, 2026 | In nspawn in systemd 233 through 259 before 260, an escape-to-host action can occur via a crafted optional config file. |
| CVE-2026-40225 | MEDIUM | 6.4 | 0.1% | Apr 10, 2026 | In udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel outp... |
| CVE-2026-40223 | MEDIUM | 5.5 | 0.1% | Apr 10, 2026 | In systemd 258 before 260, a local unprivileged user can trigger an assert when a Delegate=yes and User=<unset> unit exi... |
| CVE-2026-40023 | MEDIUM | 5.3 | 0.5% | Apr 10, 2026 | Apache Log4cxx's XMLLayout https://logging.apache.org/log4cxx/1.7.0/classlog4cxx_1_1xml_1_1XMLLayout.html , in versions... |
| CVE-2026-40021 | MEDIUM | 5.3 | 0.8% | Apr 10, 2026 | Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLa... |
| CVE-2026-35594 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (Get... |
| CVE-2026-34477 | MEDIUM | 5.9 | 0.4% | Apr 10, 2026 | The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: it addressed hostna... |
| CVE-2026-29043 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can t... |
| CVE-2026-31262 | MEDIUM | 6.1 | 0.2% | Apr 10, 2026 | Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtai... |
| CVE-2026-6067 | MEDIUM | 5.5 | 0.4% | Apr 10, 2026 | A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_... |
| CVE-2026-5774 | MEDIUM | 6.4 | 0.2% | Apr 10, 2026 | Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow a... |
| CVE-2026-5412 | MEDIUM | 6.5 | 0.4% | Apr 10, 2026 | In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated us... |
| CVE-2026-31412 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer ... |
| CVE-2026-6042 | MEDIUM | 4.8 | 0.2% | Apr 10, 2026 | A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/icon... |
| CVE-2026-33457 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | Livestatus injection in the prediction graph page in Checkmk <2.5.0b4, <2.4.0p26, and <2.3.0p47 allows an authenticated ... |
| CVE-2026-33455 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | Livestatus injection in the monitoring quicksearch in Checkmk <2.5.0b4 allows an authenticated attacker to inject livest... |
| CVE-2026-6035 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | A vulnerability has been found in code-projects Vehicle Showroom Management System 1.0. The affected element is an unkno... |
| CVE-2026-6034 | MEDIUM | 4.3 | 0.3% | Apr 10, 2026 | A flaw has been found in code-projects Vehicle Showroom Management System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-6033 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedet... |
| CVE-2026-6032 | MEDIUM | 4.3 | 0.4% | Apr 10, 2026 | A vulnerability was found in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /chec... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now