2026 CVE Vulnerabilities
51,177 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34474 | HIGH | 7.5 | 24.7% | May 6, 2026 | Sensitive data exposure leading to admin/WLAN credential leak in ZTE ZXHN H298A 1.1 and H108N 2.6. A crafted request to ... |
| CVE-2026-34473 | HIGH | 7.5 | 2.4% | May 6, 2026 | Unauthenticated DoS in ZTE H8102E, H168N, H167A, H199A, H288A, H198A, H267A, H267N, H268A, H388X, H196A, H369A, H268N, H... |
| CVE-2026-33079 | HIGH | 7.5 | 0.5% | May 6, 2026 | In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `... |
| CVE-2026-29090 | HIGH | 8.8 | 0.3% | May 6, 2026 | ### Summary A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and ... |
| CVE-2026-42503 | HIGH | 8.8 | 0.2% | May 6, 2026 | gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen... |
| CVE-2026-29080 | HIGH | 8.8 | 0.3% | May 6, 2026 | A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbit... |
| CVE-2026-23870 | HIGH | 7.5 | 1.5% | May 6, 2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo... |
| CVE-2026-21661 | HIGH | 8.4 | 0.1% | May 6, 2026 | An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Co... |
| CVE-2026-20185 | HIGH | 7.7 | 0.4% | May 6, 2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG... |
| CVE-2026-20167 | HIGH | 7.7 | 0.3% | May 6, 2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, ... |
| CVE-2026-20035 | HIGH | 7.2 | 0.4% | May 6, 2026 | A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to con... |
| CVE-2026-20034 | HIGH | 8.8 | 0.7% | May 6, 2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att... |
| CVE-2026-6788 | HIGH | 7.8 | 0.1% | May 6, 2026 | Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files. |
| CVE-2026-6787 | HIGH | 7.8 | 0.1% | May 6, 2026 | Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Pr... |
| CVE-2026-6691 | HIGH | 8.6 | 0.1% | May 6, 2026 | The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling ... |
| CVE-2026-41288 | HIGH | 7.8 | 0.1% | May 6, 2026 | Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allo... |
| CVE-2026-40562 | HIGH | 7.5 | 0.3% | May 6, 2026 | Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Gazelle incorrectl... |
| CVE-2026-6210 | HIGH | 8.7 | 0.3% | May 6, 2026 | A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. Wh... |
| CVE-2026-43283 | HIGH | 8.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ec_bhf: Fix dma_free_coherent() dma ... |
| CVE-2026-43281 | HIGH | 7.1 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: mailbox: Prevent out-of-bounds access in fw_mbox_in... |
| CVE-2026-43280 | HIGH | 7.1 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Add bounds check on pat_index to prevent OO... |
| CVE-2026-43279 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at... |
| CVE-2026-43278 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm: clear cloned request bio pointer when last clon... |
| CVE-2026-43276 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix double destroy_workqueue on service ... |
| CVE-2026-43274 | HIGH | 8.4 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: fix out-of-bounds access in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now