2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35378 | LOW | 3.3 | 0.2% | Apr 22, 2026 | A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during... |
| CVE-2026-35377 | LOW | 3.3 | 0.1% | Apr 22, 2026 | A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when uti... |
| CVE-2026-35375 | LOW | 3.3 | 0.1% | Apr 22, 2026 | A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-... |
| CVE-2026-35371 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effect... |
| CVE-2026-35367 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted... |
| CVE-2026-35362 | LOW | 3.6 | 0.2% | Apr 22, 2026 | The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) s... |
| CVE-2026-35353 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory wit... |
| CVE-2026-35346 | LOW | 3.3 | 0.2% | Apr 22, 2026 | The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. Th... |
| CVE-2026-35344 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result... |
| CVE-2026-35343 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is speci... |
| CVE-2026-35342 | LOW | 3.3 | 0.1% | Apr 22, 2026 | The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp,... |
| CVE-2026-6842 | LOW | 2.5 | 0.1% | Apr 22, 2026 | A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directo... |
| CVE-2026-22746 | LOW | 3.7 | 0.2% | Apr 22, 2026 | Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or ... |
| CVE-2026-6408 | LOW | 2.7 | 0.2% | Apr 22, 2026 | Tanium addressed an information disclosure vulnerability in Tanium Server. |
| CVE-2026-6392 | LOW | 2.7 | 0.2% | Apr 22, 2026 | Tanium addressed an information disclosure vulnerability in Threat Response. |
| CVE-2026-3307 | LOW | 2.7 | 0.3% | Apr 21, 2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin acc... |
| CVE-2026-35250 | LOW | 2.3 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35249 | LOW | 3.2 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-34312 | LOW | 2.4 | 0.2% | Apr 21, 2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea... |
| CVE-2026-34268 | LOW | 2.9 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-22018 | LOW | 3.7 | 0.3% | Apr 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-22014 | LOW | 3.8 | 0.2% | Apr 21, 2026 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events)... |
| CVE-2026-22008 | LOW | 3.7 | 0.2% | Apr 21, 2026 | Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0... |
| CVE-2026-22007 | LOW | 2.9 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-22001 | LOW | 2.7 | 0.3% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now