2026 CVE Vulnerabilities
51,949 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42039 | HIGH | 7.5 | 0.7% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively wal... |
| CVE-2026-42038 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostna... |
| CVE-2026-42035 | HIGH | 7.4 | 0.4% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadg... |
| CVE-2026-42033 | HIGH | 7.4 | 0.8% | Apr 24, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has ... |
| CVE-2026-41681 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFin... |
| CVE-2026-41680 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists... |
| CVE-2026-41678 | HIGH | 8.1 | 0.3% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() co... |
| CVE-2026-41676 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::deriv... |
| CVE-2026-41140 | HIGH | 8.7 | 0.3% | Apr 24, 2026 | Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-... |
| CVE-2026-6912 | HIGH | 8.8 | 0.4% | Apr 24, 2026 | Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in... |
| CVE-2026-41066 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in... |
| CVE-2026-40897 | HIGH | 8.8 | 0.6% | Apr 24, 2026 | Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed e... |
| CVE-2026-31667 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: Input: uinput - fix circular locking dependency wit... |
| CVE-2026-31666 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix incorrect return value after changing le... |
| CVE-2026-31665 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-after-free in timeout ob... |
| CVE-2026-31663 | HIGH | 7.8 | 0.2% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_... |
| CVE-2026-31662 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix bc_ackers underflow on duplicate GRP_ACK_... |
| CVE-2026-31656 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: fix refcount underflow in intel_engine... |
| CVE-2026-31652 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/stat: deallocate damon_call() failure leak... |
| CVE-2026-31650 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mmc: vub300: fix use-after-free on disconnect The ... |
| CVE-2026-31648 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm: filemap: fix nr_pages calculation overflow in f... |
| CVE-2026-31644 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: lan966x: fix use-after-free and leak in lan966... |
| CVE-2026-31641 | HIGH | 7.8 | 0.1% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix RxGK token loading to check bounds rxrp... |
| CVE-2026-31640 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix use of wrong skb when comparing queued R... |
| CVE-2026-31638 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Only put the call ref if one was acquired r... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now