2026 CVE Vulnerabilities
51,340 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42075 | HIGH | 8.1 | 0.6% | May 4, 2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in ... |
| CVE-2026-37461 | HIGH | 7.5 | 0.3% | May 4, 2026 | An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial ... |
| CVE-2026-29514 | HIGH | 8.8 | 0.8% | May 4, 2026 | NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environ... |
| CVE-2026-25266 | HIGH | 7.8 | 0.1% | May 4, 2026 | Memory corruption while processing IOCTL command when device is in power-save state. |
| CVE-2026-24082 | HIGH | 7.8 | 0.1% | May 4, 2026 | Memory Corruption when copying data from a freed source while executing performance counter deselect operation. |
| CVE-2026-40563 | HIGH | 8.1 | 0.5% | May 4, 2026 | Description: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas Apache Atlas expose... |
| CVE-2026-36365 | HIGH | 7.8 | 0.1% | May 4, 2026 | An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker t... |
| CVE-2026-29169 | HIGH | 7.5 | 0.6% | May 4, 2026 | A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the s... |
| CVE-2026-23918 | HIGH | 8.8 | 45.8% | May 4, 2026 | Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HT... |
| CVE-2026-6266 | HIGH | 8.3 | 0.4% | May 4, 2026 | A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external... |
| CVE-2026-34059 | HIGH | 7.5 | 0.4% | May 4, 2026 | Buffer Over-read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are... |
| CVE-2026-24072 | HIGH | 8.8 | 0.7% | May 4, 2026 | An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to re... |
| CVE-2026-3120 | HIGH | 7.2 | 1.2% | May 4, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and... |
| CVE-2026-7750 | HIGH | 8.8 | 0.5% | May 4, 2026 | A vulnerability was detected in Totolink N300RH 3.2.4-B20220812. This vulnerability affects the function setMacFilterRul... |
| CVE-2026-7749 | HIGH | 8.8 | 0.6% | May 4, 2026 | A security vulnerability has been detected in Totolink N300RH 3.2.4-B20220812. This affects the function setWanConfig of... |
| CVE-2026-7748 | HIGH | 8.8 | 0.5% | May 4, 2026 | A weakness has been identified in Totolink N300RH 3.2.4-B20220812. Affected by this issue is the function setUpgradeFW o... |
| CVE-2026-33846 | HIGH | 7.5 | 1.3% | May 4, 2026 | A heap buffer overflow vulnerability exists in the DTLS handshake fragment reassembly logic of GnuTLS. The issue arises ... |
| CVE-2026-7737 | HIGH | 7.5 | 0.6% | May 4, 2026 | A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.P... |
| CVE-2026-7736 | HIGH | 7.5 | 0.5% | May 4, 2026 | A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry o... |
| CVE-2026-29199 | HIGH | 8.1 | 0.2% | May 4, 2026 | phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_ser... |
| CVE-2026-7735 | HIGH | 7.3 | 0.4% | May 4, 2026 | A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the f... |
| CVE-2026-7734 | HIGH | 7.5 | 0.5% | May 4, 2026 | A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromByt... |
| CVE-2026-7733 | HIGH | 7.3 | 0.3% | May 4, 2026 | A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/... |
| CVE-2026-7727 | HIGH | 7.3 | 0.3% | May 4, 2026 | A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects ... |
| CVE-2026-7723 | HIGH | 7.3 | 0.4% | May 4, 2026 | A flaw has been found in PrefectHQ prefect up to 3.6.13. Affected is an unknown function of the file /api/events/in of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now