2026 CVE Vulnerabilities
53,163 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21372 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when sending IOCTL requests with invalid buffer sizes during memcpy operations. |
| CVE-2026-21371 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when retrieving output buffer with insufficient size validation. |
| CVE-2026-21367 | HIGH | 7.5 | 0.2% | Apr 6, 2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. |
| CVE-2026-34885 | HIGH | 8.5 | 1.7% | Apr 6, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi... |
| CVE-2026-33540 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mod... |
| CVE-2026-33510 | HIGH | 8.8 | 0.2% | Apr 6, 2026 | Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been disco... |
| CVE-2026-29047 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user... |
| CVE-2026-26026 | HIGH | 7.2 | 0.4% | Apr 6, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, template injection by an administ... |
| CVE-2026-30078 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. Fo... |
| CVE-2026-3524 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in Serv... |
| CVE-2026-5648 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /u... |
| CVE-2026-5646 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A security vulnerability has been detected in code-projects Easy Blog Site 1.0. Affected by this issue is some unknown f... |
| CVE-2026-5645 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A weakness has been identified in projectworlds Car Rental System 1.0. Affected by this vulnerability is an unknown func... |
| CVE-2026-5673 | HIGH | 7.1 | 0.2% | Apr 6, 2026 | A flaw was found in libtheora. This heap-based out-of-bounds read vulnerability exists within the AVI (Audio Video Inter... |
| CVE-2026-5642 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th... |
| CVE-2026-5637 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A security vulnerability has been detected in projectworlds Car Rental System 1.0. This vulnerability affects unknown co... |
| CVE-2026-5634 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A vulnerability was identified in projectworlds Car Rental Project 1.0. Affected by this vulnerability is an unknown fun... |
| CVE-2026-5633 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the compone... |
| CVE-2026-31409 | HIGH | 8.8 | 0.5% | Apr 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: unset conn->binding on failed binding reques... |
| CVE-2026-31408 | HIGH | 8.8 | 0.3% | Apr 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: Fix use-after-free in sco_recv_fram... |
| CVE-2026-31407 | HIGH | 7.1 | 0.2% | Apr 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: add missing netlink policy va... |
| CVE-2026-31406 | HIGH | 7.8 | 0.2% | Apr 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix work re-schedule after cancel in xfrm_nat... |
| CVE-2026-5632 | HIGH | 7.3 | 0.4% | Apr 6, 2026 | A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component H... |
| CVE-2026-5631 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data... |
| CVE-2026-5629 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | A vulnerability was detected in Belkin F9K1015 1.00.10. The affected element is the function formSetFirewall of the file... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now