2026 CVE Vulnerabilities
52,054 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31435 | HIGH | 8.8 | 0.3% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfs: Fix read abandonment during retry Under cer... |
| CVE-2026-0539 | HIGH | 8.5 | 0.1% | Apr 22, 2026 | Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate th... |
| CVE-2026-6857 | HIGH | 7.5 | 0.7% | Apr 22, 2026 | A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggre... |
| CVE-2026-6855 | HIGH | 7.1 | 0.2% | Apr 22, 2026 | A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handl... |
| CVE-2026-6848 | HIGH | 8.1 | 0.3% | Apr 22, 2026 | A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as ... |
| CVE-2026-33260 | HIGH | 7.5 | 0.5% | Apr 22, 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni... |
| CVE-2026-33258 | HIGH | 7.5 | 0.6% | Apr 22, 2026 | By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressi... |
| CVE-2026-33257 | HIGH | 7.5 | 0.5% | Apr 22, 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni... |
| CVE-2026-33256 | HIGH | 7.5 | 0.6% | Apr 22, 2026 | An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a deni... |
| CVE-2026-6846 | HIGH | 7.8 | 0.2% | Apr 22, 2026 | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Ext... |
| CVE-2026-4132 | HIGH | 7.2 | 1.0% | Apr 22, 2026 | The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec... |
| CVE-2026-31433 | HIGH | 8.8 | 0.6% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potencial OOB in get_file_all_info() for... |
| CVE-2026-31432 | HIGH | 8.8 | 0.5% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix OOB write in QUERY_INFO for compound req... |
| CVE-2026-31431 | HIGH | 7.8 | 94.5% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-pla... |
| CVE-2026-6022 | HIGH | 7.5 | 0.3% | Apr 22, 2026 | In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vuln... |
| CVE-2026-40542 | HIGH | 7.3 | 0.5% | Apr 22, 2026 | Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-... |
| CVE-2026-22754 | HIGH | 7.5 | 0.3% | Apr 22, 2026 | Vulnerability in Spring Spring Security. If an application uses <sec:intercept-url servlet-path="/servlet-path" pattern=... |
| CVE-2026-22753 | HIGH | 7.5 | 0.2% | Apr 22, 2026 | Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMat... |
| CVE-2026-22747 | HIGH | 8.1 | 0.3% | Apr 22, 2026 | Vulnerability in Spring Spring Security. SubjectX500PrincipalExtractor does not correctly handle certain malformed X.509... |
| CVE-2026-6834 | HIGH | 7.1 | 0.3% | Apr 22, 2026 | The a+HRD developed by aEnrich has a Missing Authorization vulnerability, allowing authenticated remote attackers to arb... |
| CVE-2026-6833 | HIGH | 7.1 | 0.3% | Apr 22, 2026 | The a+HRD developed by aEnrich has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbi... |
| CVE-2026-5398 | HIGH | 8.4 | 0.2% | Apr 22, 2026 | The implementation of TIOCNOTTY failed to clear a back-pointer from the structure representing the controlling terminal ... |
| CVE-2026-41458 | HIGH | 8.2 | 0.4% | Apr 22, 2026 | OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows u... |
| CVE-2026-41146 | HIGH | 8.7 | 0.3% | Apr 22, 2026 | facil.io is a C micro-framework for web applications. Prior to commit 5128747363055201d3ecf0e29bf0a961703c9fa0, `fio_jso... |
| CVE-2026-41145 | HIGH | 8.2 | 0.3% | Apr 22, 2026 | MinIO is a high-performance object storage system. Starting in RELEASE.2023-05-18T00-05-36Z and prior to RELEASE.2026-04... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now