2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6348 | CRITICAL | 9.3 | 0.2% | Apr 16, 2026 | WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local... |
| CVE-2026-40962 | CRITICAL | 9.8 | 0.1% | Apr 16, 2026 | FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data ... |
| CVE-2026-40504 | CRITICAL | 9.8 | 0.6% | Apr 16, 2026 | Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows ... |
| CVE-2026-40959 | CRITICAL | 9.3 | 0.2% | Apr 16, 2026 | Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod. |
| CVE-2026-4880 | CRITICAL | 9.8 | 0.5% | Apr 16, 2026 | The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPres... |
| CVE-2026-6388 | CRITICAL | 9.1 | 0.4% | Apr 15, 2026 | A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an... |
| CVE-2026-40173 | CRITICAL | 9.4 | 0.5% | Apr 15, 2026 | Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential d... |
| CVE-2026-6296 | CRITICAL | 9.6 | 0.3% | Apr 15, 2026 | Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform ... |
| CVE-2026-5189 | CRITICAL | 9.2 | 0.5% | Apr 15, 2026 | CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unau... |
| CVE-2026-6290 | CRITICAL | 9.1 | 0.2% | Apr 15, 2026 | Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with... |
| CVE-2026-30993 | CRITICAL | 9.8 | 0.5% | Apr 15, 2026 | Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() functio... |
| CVE-2026-20186 | CRITICAL | 9.9 | 5.9% | Apr 15, 2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra... |
| CVE-2026-20184 | CRITICAL | 9.8 | 0.5% | Apr 15, 2026 | A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed a... |
| CVE-2026-20180 | CRITICAL | 9.9 | 6.0% | Apr 15, 2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra... |
| CVE-2026-20147 | CRITICAL | 9.9 | 10.9% | Apr 15, 2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary comman... |
| CVE-2026-5387 | CRITICAL | 9.3 | 0.4% | Apr 15, 2026 | The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simula... |
| CVE-2026-30625 | CRITICAL | 9.8 | 1.0% | Apr 15, 2026 | Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The applica... |
| CVE-2026-33808 | CRITICAL | 9.1 | 0.5% | Apr 15, 2026 | Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express middleware when Fastify... |
| CVE-2026-33807 | CRITICAL | 9.1 | 0.4% | Apr 15, 2026 | @fastify/express v4.0.4 and earlier contains a path handling bug in the onRegister function that causes middleware paths... |
| CVE-2026-3461 | CRITICAL | 9.8 | 0.5% | Apr 15, 2026 | The Visa Acceptance Solutions plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and inc... |
| CVE-2026-39842 | CRITICAL | 9.9 | 0.9% | Apr 15, 2026 | OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulne... |
| CVE-2026-1555 | CRITICAL | 9.8 | 1.0% | Apr 15, 2026 | The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i... |
| CVE-2026-39399 | CRITICAL | 9.6 | 0.5% | Apr 14, 2026 | NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend... |
| CVE-2026-35589 | CRITICAL | 9.3 | 0.2% | Apr 14, 2026 | nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerabili... |
| CVE-2026-35033 | CRITICAL | 9.1 | 0.3% | Apr 14, 2026 | Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now