2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5980 | HIGH | 8.8 | 0.7% | Apr 9, 2026 | A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /g... |
| CVE-2026-5979 | HIGH | 8.8 | 0.7% | Apr 9, 2026 | A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ ... |
| CVE-2026-5447 | HIGH | 7.5 | 0.2% | Apr 9, 2026 | Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when conve... |
| CVE-2026-5446 | HIGH | 7.1 | 0.3% | Apr 9, 2026 | In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every applicati... |
| CVE-2026-40093 | HIGH | 8.1 | 0.3% | Apr 9, 2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestam... |
| CVE-2026-4436 | HIGH | 8.6 | 0.4% | Apr 9, 2026 | A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant i... |
| CVE-2026-35577 | HIGH | 8.1 | 0.2% | Apr 9, 2026 | Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.... |
| CVE-2026-35063 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with r... |
| CVE-2026-34734 | HIGH | 7.8 | 0.2% | Apr 9, 2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utilit... |
| CVE-2026-34487 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apach... |
| CVE-2026-34486 | HIGH | 7.5 | 81.2% | Apr 9, 2026 | Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypas... |
| CVE-2026-34483 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue ... |
| CVE-2026-29923 | HIGH | 7.8 | 0.1% | Apr 9, 2026 | The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a... |
| CVE-2026-29146 | HIGH | 7.5 | 6.3% | Apr 9, 2026 | Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apach... |
| CVE-2026-29129 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from... |
| CVE-2026-24880 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via inva... |
| CVE-2026-35556 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve cre... |
| CVE-2026-35186 | HIGH | 7.5 | 0.2% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backe... |
| CVE-2026-34946 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta... |
| CVE-2026-34943 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a possible panic w... |
| CVE-2026-34941 | HIGH | 8.1 | 0.4% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime contains a vulnerability wh... |
| CVE-2026-40072 | HIGH | 7.2 | 0.2% | Apr 9, 2026 | web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web... |
| CVE-2026-40070 | HIGH | 8.1 | 0.1% | Apr 9, 2026 | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certi... |
| CVE-2026-40069 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection o... |
| CVE-2026-39983 | HIGH | 8.6 | 2.2% | Apr 9, 2026 | basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n)... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now