2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33516 | CRITICAL | 9.1 | 0.4% | Apr 17, 2026 | xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP ca... |
| CVE-2026-40525 | CRITICAL | 9.1 | 0.6% | Apr 17, 2026 | OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route su... |
| CVE-2026-40518 | CRITICAL | 9.1 | 0.4% | Apr 17, 2026 | ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-m... |
| CVE-2026-6284 | CRITICAL | 9.3 | 0.4% | Apr 17, 2026 | An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to syst... |
| CVE-2026-41153 | CRITICAL | 9.8 | 0.3% | Apr 17, 2026 | In JetBrains Junie before 252.549.29 command execution was possible via malicious project file |
| CVE-2026-37749 | CRITICAL | 9.8 | 0.7% | Apr 17, 2026 | A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attack... |
| CVE-2026-6443 | CRITICAL | 9.8 | 0.5% | Apr 17, 2026 | All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to ... |
| CVE-2026-34018 | CRITICAL | 9.8 | 0.2% | Apr 17, 2026 | An SQL injection vulnerability exists in CubeCart prior to 6.6.0, which may allow an attacker to execute an arbitrary SQ... |
| CVE-2026-40322 | CRITICAL | 9 | 0.3% | Apr 16, 2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, Mermaid diagrams are rendere... |
| CVE-2026-33122 | CRITICAL | 9.8 | 0.4% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-33082 | CRITICAL | 9.8 | 0.3% | Apr 16, 2026 | DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerab... |
| CVE-2026-27820 | CRITICAL | 9.8 | 0.6% | Apr 16, 2026 | zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 a... |
| CVE-2026-5426 | CRITICAL | 9.1 | 1.0% | Apr 16, 2026 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 all... |
| CVE-2026-37347 | CRITICAL | 9.1 | 0.3% | Apr 16, 2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_e... |
| CVE-2026-37345 | CRITICAL | 9.8 | 0.3% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_pa... |
| CVE-2026-37340 | CRITICAL | 9.8 | 0.3% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php... |
| CVE-2026-37339 | CRITICAL | 9.8 | 0.3% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php... |
| CVE-2026-37338 | CRITICAL | 9.4 | 0.3% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. |
| CVE-2026-33804 | CRITICAL | 9.1 | 0.3% | Apr 16, 2026 | @fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplica... |
| CVE-2026-6270 | CRITICAL | 9.1 | 0.5% | Apr 16, 2026 | @fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instance... |
| CVE-2026-31843 | CRITICAL | 10 | 2.8% | Apr 16, 2026 | The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update e... |
| CVE-2026-3596 | CRITICAL | 9.8 | 0.8% | Apr 16, 2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu... |
| CVE-2026-22619 | CRITICAL | 9.9 | 0.3% | Apr 16, 2026 | Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to a... |
| CVE-2026-6350 | CRITICAL | 9.8 | 0.8% | Apr 16, 2026 | MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remo... |
| CVE-2026-6349 | CRITICAL | 9.8 | 2.1% | Apr 16, 2026 | The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now