2026 CVE Vulnerabilities
52,080 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40583 | HIGH | 8.2 | 0.4% | Apr 21, 2026 | UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vo... |
| CVE-2026-40568 | HIGH | 8.5 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripti... |
| CVE-2026-38834 | HIGH | 7.3 | 1.3% | Apr 21, 2026 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via th... |
| CVE-2026-24189 | HIGH | 8.2 | 0.3% | Apr 21, 2026 | NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds re... |
| CVE-2026-24177 | HIGH | 7.7 | 0.2% | Apr 21, 2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A succ... |
| CVE-2026-21571 | HIGH | 8.8 | 1.3% | Apr 21, 2026 | This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.... |
| CVE-2026-37748 | HIGH | 7.2 | 0.8% | Apr 21, 2026 | Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php a... |
| CVE-2026-5789 | HIGH | 7.8 | 0.1% | Apr 21, 2026 | Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execut... |
| CVE-2026-3298 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the dat... |
| CVE-2026-31019 | HIGH | 8.8 | 0.6% | Apr 21, 2026 | In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict... |
| CVE-2026-31018 | HIGH | 8.8 | 0.3% | Apr 21, 2026 | In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not appl... |
| CVE-2026-6784 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption a... |
| CVE-2026-6782 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6781 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 15... |
| CVE-2026-6780 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 15... |
| CVE-2026-6776 | HIGH | 7.8 | 0.1% | Apr 21, 2026 | Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ... |
| CVE-2026-6773 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150... |
| CVE-2026-6772 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ES... |
| CVE-2026-6769 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunder... |
| CVE-2026-6766 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ES... |
| CVE-2026-6761 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thund... |
| CVE-2026-6759 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderb... |
| CVE-2026-6758 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150... |
| CVE-2026-6756 | HIGH | 7.5 | 0.2% | Apr 21, 2026 | Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150. |
| CVE-2026-6754 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Fire... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now