2026 CVE Vulnerabilities
52,006 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4922 | HIGH | 8.1 | 0.2% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and... |
| CVE-2026-35368 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | A vulnerability exists in the chroot utility of uutils coreutils when using the --userspec option. The utility resolves ... |
| CVE-2026-35352 | HIGH | 7 | 0.1% | Apr 22, 2026 | A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility cre... |
| CVE-2026-35349 | HIGH | 7.7 | 0.2% | Apr 22, 2026 | A vulnerability in the rm utility of uutils coreutils allows a bypass of the --preserve-root protection. The implementat... |
| CVE-2026-35341 | HIGH | 7.1 | 0.2% | Apr 22, 2026 | A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. Wh... |
| CVE-2026-35338 | HIGH | 7.3 | 0.2% | Apr 22, 2026 | A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. Th... |
| CVE-2026-35548 | HIGH | 8.5 | 0.2% | Apr 22, 2026 | An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix ... |
| CVE-2026-6861 | HIGH | 7.1 | 0.1% | Apr 22, 2026 | A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially craf... |
| CVE-2026-6859 | HIGH | 8.8 | 0.4% | Apr 22, 2026 | A flaw was found in InstructLab. The `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from... |
| CVE-2026-5750 | HIGH | 7.6 | 0.2% | Apr 22, 2026 | An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated us... |
| CVE-2026-5749 | HIGH | 8.7 | 0.3% | Apr 22, 2026 | Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain ... |
| CVE-2026-41651 | HIGH | 8.8 | 0.5% | Apr 22, 2026 | PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, ... |
| CVE-2026-33610 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondar... |
| CVE-2026-33602 | HIGH | 8.2 | 0.7% | Apr 22, 2026 | A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, trig... |
| CVE-2026-33599 | HIGH | 8.1 | 0.3% | Apr 22, 2026 | A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via eith... |
| CVE-2026-33597 | HIGH | 7.5 | 0.3% | Apr 22, 2026 | PRSD detection denial of service |
| CVE-2026-33595 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 conn... |
| CVE-2026-33594 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH bac... |
| CVE-2026-33593 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query. |
| CVE-2026-33254 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSd... |
| CVE-2026-31530 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: cxl/port: Fix use after free of parent_port in cxl_... |
| CVE-2026-31528 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf: Make sure to use pmu_ctx->pmu for groups Oli... |
| CVE-2026-31527 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use generic driver_override ... |
| CVE-2026-31525 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix undefined behavior in interpreter sdiv/smo... |
| CVE-2026-31516 | HIGH | 7.8 | 0.1% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: prevent policy_hthresh.work from racing with ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now