2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33273 | HIGH | 7.2 | 0.2% | Apr 8, 2026 | Unrestricted upload of file with dangerous type issue exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability ... |
| CVE-2026-24913 | HIGH | 8.8 | 0.3% | Apr 8, 2026 | SQL Injection vulnerability exists in MATCHA INVOICE 2.6.6 and earlier. If this vulnerability is exploited, information ... |
| CVE-2026-5726 | HIGH | 8.4 | 0.3% | Apr 8, 2026 | ASDA-Soft Stack-based Buffer Overflow Vulnerability |
| CVE-2026-3499 | HIGH | 8.8 | 0.2% | Apr 8, 2026 | The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to C... |
| CVE-2026-33810 | HIGH | 8.2 | 0.3% | Apr 8, 2026 | When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to w... |
| CVE-2026-32283 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection c... |
| CVE-2026-32281 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a ve... |
| CVE-2026-32280 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cert... |
| CVE-2026-27144 | HIGH | 7.1 | 0.3% | Apr 8, 2026 | The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented... |
| CVE-2026-27140 | HIGH | 8.8 | 0.7% | Apr 8, 2026 | SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at ... |
| CVE-2026-3357 | HIGH | 8.8 | 0.5% | Apr 8, 2026 | IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the sys... |
| CVE-2026-1346 | HIGH | 7.8 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-1343 | HIGH | 7.2 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-5747 | HIGH | 8.7 | 0.2% | Apr 8, 2026 | An out-of-bounds write issue in the virtio PCI transport in Firecracker 1.13.0 through 1.14.3 and 1.15.0 on x86_64 and a... |
| CVE-2026-1342 | HIGH | 7.9 | 0.2% | Apr 8, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-39937 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki... |
| CVE-2026-39847 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handle... |
| CVE-2026-35406 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS que... |
| CVE-2026-34765 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5,... |
| CVE-2026-34580 | HIGH | 7.5 | 0.2% | Apr 7, 2026 | Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name;... |
| CVE-2026-34079 | HIGH | 7.5 | 0.3% | Apr 7, 2026 | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes out... |
| CVE-2026-31790 | HIGH | 7.5 | 1.2% | Apr 7, 2026 | Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an ... |
| CVE-2026-28390 | HIGH | 7.5 | 1.0% | Apr 7, 2026 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer de... |
| CVE-2026-28389 | HIGH | 7.5 | 1.0% | Apr 7, 2026 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer derefe... |
| CVE-2026-28388 | HIGH | 7.5 | 1.1% | Apr 7, 2026 | Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference mi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now