2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5964 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to injec... |
| CVE-2026-5963 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to injec... |
| CVE-2026-6644 | CRITICAL | 9.1 | 1.5% | Apr 20, 2026 | A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrati... |
| CVE-2026-6643 | CRITICAL | 9.9 | 0.5% | Apr 20, 2026 | A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unb... |
| CVE-2026-32956 | CRITICAL | 9.8 | 0.5% | Apr 20, 2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in proces... |
| CVE-2026-41242 | CRITICAL | 9.8 | 0.7% | Apr 18, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers... |
| CVE-2026-40494 | CRITICAL | 9.8 | 0.3% | Apr 18, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P... |
| CVE-2026-40493 | CRITICAL | 9.8 | 0.4% | Apr 18, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P... |
| CVE-2026-40492 | CRITICAL | 9.8 | 0.3% | Apr 18, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P... |
| CVE-2026-40487 | CRITICAL | 9 | 0.2% | Apr 18, 2026 | Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authen... |
| CVE-2026-40572 | CRITICAL | 9 | 0.2% | Apr 18, 2026 | NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (Memo... |
| CVE-2026-40317 | CRITICAL | 9.3 | 0.2% | Apr 18, 2026 | NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (Jump... |
| CVE-2026-40582 | CRITICAL | 9.1 | 0.5% | Apr 18, 2026 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint va... |
| CVE-2026-40484 | CRITICAL | 9.1 | 0.9% | Apr 18, 2026 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functional... |
| CVE-2026-40324 | CRITICAL | 9.1 | 0.9% | Apr 18, 2026 | Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's... |
| CVE-2026-5720 | CRITICAL | 9.1 | 0.7% | Apr 17, 2026 | miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause... |
| CVE-2026-40478 | CRITICAL | 9 | 0.8% | Apr 17, 2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co... |
| CVE-2026-40477 | CRITICAL | 9 | 0.9% | Apr 17, 2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co... |
| CVE-2026-40351 | CRITICAL | 9.8 | 0.6% | Apr 17, 2026 | FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScri... |
| CVE-2026-40258 | CRITICAL | 9.1 | 0.4% | Apr 17, 2026 | The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 hav... |
| CVE-2026-29013 | CRITICAL | 9.8 | 0.3% | Apr 17, 2026 | libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in ... |
| CVE-2026-33689 | CRITICAL | 9.1 | 0.5% | Apr 17, 2026 | xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentic... |
| CVE-2026-23500 | CRITICAL | 9.1 | 0.9% | Apr 17, 2026 | Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versio... |
| CVE-2026-40342 | CRITICAL | 9.9 | 0.7% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the exte... |
| CVE-2026-35546 | CRITICAL | 9.8 | 0.6% | Apr 17, 2026 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now