2026 CVE Vulnerabilities
51,441 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-37457 | HIGH | 7.5 | 0.4% | May 1, 2026 | An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of F... |
| CVE-2026-42485 | HIGH | 7.5 | 0.3% | May 1, 2026 | AGL agl-service-can-low-level contains a stack buffer overflow in the uds-c library. The send_diagnostic_request functio... |
| CVE-2026-42469 | HIGH | 8.6 | 0.4% | May 1, 2026 | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser... |
| CVE-2026-42468 | HIGH | 8.8 | 0.4% | May 1, 2026 | Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_pcap.cpp , the parser's ... |
| CVE-2026-42467 | HIGH | 7.5 | 0.3% | May 1, 2026 | An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939... |
| CVE-2026-37538 | HIGH | 7.5 | 0.3% | May 1, 2026 | Buffer overflow vulnerability in socketcand 0.4.2 in file socketcand.c in function main allows attackers to cause a deni... |
| CVE-2026-37537 | HIGH | 8.1 | 0.2% | May 1, 2026 | collin80/Open-SAE-J1939 thru commit 744024d4306bc387857dfce439558336806acb06 (2023-03-08) contains an integer underflow ... |
| CVE-2026-37536 | HIGH | 8.8 | 0.3% | May 1, 2026 | miaofng/uds-c commit e506334e270d77b20c0bc259ac6c7d8c9b702b7a (2016-10-05) contains a stack buffer overflow in send_diag... |
| CVE-2026-37535 | HIGH | 7.1 | 0.2% | May 1, 2026 | openxc/isotp-c thru commit 5a5d19245f65189202719321facd49ce6f5d46ac (2021-08-09) contains an out-of-bounds read in the I... |
| CVE-2026-37532 | HIGH | 7.1 | 0.2% | May 1, 2026 | AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_re... |
| CVE-2026-37530 | HIGH | 7.5 | 0.4% | May 1, 2026 | AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_re... |
| CVE-2026-37526 | HIGH | 7.8 | 0.1% | May 1, 2026 | AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision comman... |
| CVE-2026-37525 | HIGH | 7.8 | 0.1% | May 1, 2026 | AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision ... |
| CVE-2026-42471 | HIGH | 8.1 | 1.8% | May 1, 2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) cal... |
| CVE-2026-37554 | HIGH | 7.5 | 0.4% | May 1, 2026 | An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The v... |
| CVE-2026-37552 | HIGH | 8.4 | 0.3% | May 1, 2026 | Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) rec... |
| CVE-2026-37504 | HIGH | 7.5 | 0.3% | May 1, 2026 | Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyControlle... |
| CVE-2026-22167 | HIGH | 7.8 | 0.1% | May 1, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbit... |
| CVE-2026-22166 | HIGH | 8.1 | 0.3% | May 1, 2026 | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash ... |
| CVE-2026-22165 | HIGH | 8.1 | 0.3% | May 1, 2026 | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF cras... |
| CVE-2026-43507 | HIGH | 7.5 | 0.3% | May 1, 2026 | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur v... |
| CVE-2026-43506 | HIGH | 7.5 | 0.3% | May 1, 2026 | An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur v... |
| CVE-2026-43057 | HIGH | 7.5 | 0.4% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic on IPV6_CSUM... |
| CVE-2026-43056 | HIGH | 7.8 | 0.1% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in add_adev() error p... |
| CVE-2026-43055 | HIGH | 7.5 | 0.4% | May 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: file: Use kzalloc_flex for aio_cmd T... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now