2026 CVE Vulnerabilities
53,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34791 | HIGH | 8.8 | 1.3% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet... |
| CVE-2026-34790 | HIGH | 8.1 | 0.6% | Apr 2, 2026 | Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in ... |
| CVE-2026-34728 | HIGH | 8.1 | 0.7% | Apr 2, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handl... |
| CVE-2026-33641 | HIGH | 7.8 | 0.9% | Apr 2, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic config... |
| CVE-2026-33544 | HIGH | 7.7 | 0.3% | Apr 2, 2026 | Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations ... |
| CVE-2026-31937 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a p... |
| CVE-2026-31935 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation ... |
| CVE-2026-31934 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexi... |
| CVE-2026-5338 | HIGH | 7.2 | 4.4% | Apr 2, 2026 | A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the function action_set_system... |
| CVE-2026-3692 | HIGH | 8.8 | 0.4% | Apr 2, 2026 | In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may cr... |
| CVE-2026-35168 | HIGH | 8.8 | 0.7% | Apr 2, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th... |
| CVE-2026-31933 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause S... |
| CVE-2026-31932 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can le... |
| CVE-2026-31931 | HIGH | 7.5 | 0.4% | Apr 2, 2026 | Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule ke... |
| CVE-2026-2701 | HIGH | 8.8 | 48.8% | Apr 2, 2026 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. |
| CVE-2026-29782 | HIGH | 7.2 | 0.6% | Apr 2, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th... |
| CVE-2026-28805 | HIGH | 8.8 | 0.5% | Apr 2, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, mu... |
| CVE-2026-26928 | HIGH | 8.7 | 0.2% | Apr 2, 2026 | SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dyna... |
| CVE-2026-4636 | HIGH | 8.1 | 0.3% | Apr 2, 2026 | A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) po... |
| CVE-2026-4634 | HIGH | 7.5 | 0.5% | Apr 2, 2026 | A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted ... |
| CVE-2026-4282 | HIGH | 7.4 | 0.4% | Apr 2, 2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso... |
| CVE-2026-3872 | HIGH | 7.3 | 0.4% | Apr 2, 2026 | A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass... |
| CVE-2026-23415 | HIGH | 7.8 | 0.1% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and ... |
| CVE-2026-23413 | HIGH | 7.8 | 0.1% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback... |
| CVE-2026-23412 | HIGH | 7.8 | 0.1% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now