2026 CVE Vulnerabilities
53,108 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31281 | HIGH | 8 | 0.3% | Apr 13, 2026 | Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a... |
| CVE-2026-30999 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Servi... |
| CVE-2026-30998 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows att... |
| CVE-2026-30997 | HIGH | 7.5 | 0.3% | Apr 13, 2026 | An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cau... |
| CVE-2026-1462 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow S... |
| CVE-2026-31426 | HIGH | 7 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acp... |
| CVE-2026-31419 | HIGH | 7.8 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broad... |
| CVE-2026-31417 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix overflow when accumulating packets Ad... |
| CVE-2026-34476 | HIGH | 7.1 | 0.3% | Apr 13, 2026 | Server-Side Request Forgery via SW-URL Header vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalk... |
| CVE-2026-6204 | HIGH | 7.2 | 7.5% | Apr 13, 2026 | LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Bina... |
| CVE-2026-35337 | HIGH | 8.8 | 1.0% | Apr 13, 2026 | Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When p... |
| CVE-2026-0233 | HIGH | 8.8 | 0.2% | Apr 13, 2026 | A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an ... |
| CVE-2026-6168 | HIGH | 8.8 | 0.6% | Apr 13, 2026 | A flaw has been found in TOTOLINK A7000R up to 9.1.0u.6115. The affected element is the function setWiFiEasyGuestCfg of ... |
| CVE-2026-6167 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability was detected in code-projects Faculty Management System 1.0. Impacted is an unknown function of the file... |
| CVE-2026-6166 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security vulnerability has been detected in code-projects Vehicle Showroom Management System 1.0. This issue affects s... |
| CVE-2026-40436 | HIGH | 7.5 | 0.2% | Apr 13, 2026 | The ZTE ZXEDM iEMS product has a password reset vulnerability for any user.Because the management of the cloud EMS porta... |
| CVE-2026-3830 | HIGH | 8.6 | 0.4% | Apr 13, 2026 | The Product Filter for WooCommerce by WBW WordPress plugin before 3.1.3 does not sanitize and escape a parameter before ... |
| CVE-2026-6165 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A weakness has been identified in code-projects Vehicle Showroom Management System 1.0. This vulnerability affects unkno... |
| CVE-2026-6164 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security flaw has been discovered in code-projects Lost and Found Thing Management 1.0. This affects an unknown part o... |
| CVE-2026-6163 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability was identified in code-projects Lost and Found Thing Management 1.0. Affected by this issue is some unkn... |
| CVE-2026-40447 | HIGH | 7.5 | 0.2% | Apr 13, 2026 | Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affect... |
| CVE-2026-21010 | HIGH | 7.8 | 0.1% | Apr 13, 2026 | Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged fu... |
| CVE-2026-6161 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chat... |
| CVE-2026-6158 | HIGH | 7.3 | 1.4% | Apr 13, 2026 | A flaw has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setUpgradeUboot of the file upgra... |
| CVE-2026-35553 | HIGH | 8.4 | 0.1% | Apr 13, 2026 | Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may ex... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now