2026 CVE Vulnerabilities
53,226 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22767 | HIGH | 7.3 | 0.2% | Apr 1, 2026 | Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged att... |
| CVE-2026-24096 | HIGH | 8.8 | 0.2% | Apr 1, 2026 | Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5... |
| CVE-2026-0932 | HIGH | 7.3 | 0.2% | Apr 1, 2026 | Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in... |
| CVE-2026-23899 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | An improper access check allows unauthorized access to webservice endpoints. |
| CVE-2026-23898 | HIGH | 7.2 | 0.5% | Apr 1, 2026 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. |
| CVE-2026-21630 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint. |
| CVE-2026-21629 | HIGH | 7.3 | 0.2% | Apr 1, 2026 | The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was pote... |
| CVE-2026-5261 | HIGH | 7.3 | 0.4% | Apr 1, 2026 | A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uplo... |
| CVE-2026-23411 | HIGH | 7.8 | 0.1% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs acce... |
| CVE-2026-23410 | HIGH | 7.8 | 0.1% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is... |
| CVE-2026-23408 | HIGH | 7.8 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_... |
| CVE-2026-23407 | HIGH | 7.8 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table... |
| CVE-2026-23406 | HIGH | 7.8 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro... |
| CVE-2026-28265 | HIGH | 7.1 | 0.1% | Apr 1, 2026 | PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access cou... |
| CVE-2026-27101 | HIGH | 7.2 | 0.4% | Apr 1, 2026 | Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application version(s) 5.28.00.xx to 5.32.00.xx, contain(s) an Impro... |
| CVE-2026-5258 | HIGH | 7.3 | 0.6% | Apr 1, 2026 | A vulnerability was found in Sanster IOPaint 1.5.3. Impacted is the function _get_file of the file iopaint/file_manager/... |
| CVE-2026-4748 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | A regression in the way hashes were calculated caused rules containing the address range syntax (x.x.x.x - y.y.y.y) that... |
| CVE-2026-5292 | HIGH | 8.8 | 0.2% | Apr 1, 2026 | Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ... |
| CVE-2026-5287 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code insid... |
| CVE-2026-5286 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via ... |
| CVE-2026-5285 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-5284 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render... |
| CVE-2026-5282 | HIGH | 8.1 | 0.2% | Apr 1, 2026 | Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of ... |
| CVE-2026-5281 | HIGH | 8.8 | 5.0% | Apr 1, 2026 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render... |
| CVE-2026-5280 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now