2026 CVE Vulnerabilities
45,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41179 | CRITICAL | 9.8 | 9.2% | Apr 23, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting i... |
| CVE-2026-41176 | CRITICAL | 9.8 | 34.7% | Apr 23, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC end... |
| CVE-2026-29198 | CRITICAL | 9.8 | 0.4% | Apr 23, 2026 | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability c... |
| CVE-2026-41167 | CRITICAL | 9.1 | 0.5% | Apr 22, 2026 | Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jell... |
| CVE-2026-33656 | CRITICAL | 9.1 | 0.5% | Apr 22, 2026 | EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formu... |
| CVE-2026-33471 | CRITICAL | 9.6 | 0.2% | Apr 22, 2026 | nimiq-block contains block primitives to be used in Nimiq's Rust implementation. `SkipBlockProof::verify` computes its q... |
| CVE-2026-41468 | CRITICAL | 9.3 | 0.4% | Apr 22, 2026 | Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives.... |
| CVE-2026-34415 | CRITICAL | 9.8 | 3.6% | Apr 22, 2026 | Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder con... |
| CVE-2026-26354 | CRITICAL | 9.8 | 0.5% | Apr 22, 2026 | Dell PowerProtect Data Domain with Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.6, LTS2... |
| CVE-2026-32885 | CRITICAL | 9.1 | 0.4% | Apr 22, 2026 | DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2... |
| CVE-2026-6356 | CRITICAL | 9.6 | 0.3% | Apr 22, 2026 | A vulnerability in the web application allows standard users to escalate their privileges to those of a super administra... |
| CVE-2026-33608 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes sai... |
| CVE-2026-33598 | CRITICAL | 9.1 | 1.1% | Apr 22, 2026 | A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddres... |
| CVE-2026-31501 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ti: icssg-prueth: fix use-after-free of CPPI d... |
| CVE-2026-31478 | CRITICAL | 9.8 | 0.5% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: replace hardcoded hdr2_len with offsetof() i... |
| CVE-2026-31463 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: iomap: fix invalid folio access when i_blkbits diff... |
| CVE-2026-31448 | CRITICAL | 9.4 | 0.4% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: avoid infinite loops caused by residual data ... |
| CVE-2026-31444 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free and NULL deref in smb_gra... |
| CVE-2026-31436 | CRITICAL | 9.8 | 0.5% | Apr 22, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix possible wrong descriptor comp... |
| CVE-2026-6235 | CRITICAL | 9.8 | 0.6% | Apr 22, 2026 | The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests'... |
| CVE-2026-4119 | CRITICAL | 9.1 | 0.7% | Apr 22, 2026 | The Create DB Tables plugin for WordPress is vulnerable to authorization bypass in all versions up to and including 1.2.... |
| CVE-2026-6023 | CRITICAL | 9.8 | 0.5% | Apr 22, 2026 | In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecu... |
| CVE-2026-41304 | CRITICAL | 9.8 | 2.2% | Apr 22, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the Clo... |
| CVE-2026-41144 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applicati... |
| CVE-2026-41064 | CRITICAL | 9.3 | 0.3% | Apr 22, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now