2026 CVE Vulnerabilities
45,094 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35477 | CRITICAL | 9.9 | 0.3% | Apr 8, 2026 | InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PA... |
| CVE-2026-2942 | CRITICAL | 9.8 | 0.6% | Apr 8, 2026 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2026-33466 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and po... |
| CVE-2026-31017 | CRITICAL | 9.1 | 0.2% | Apr 8, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frapp... |
| CVE-2026-33229 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8... |
| CVE-2026-31040 | CRITICAL | 9.8 | 0.6% | Apr 8, 2026 | A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-fil... |
| CVE-2026-39394 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-5300 | CRITICAL | 9.1 | 0.2% | Apr 8, 2026 | Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modif... |
| CVE-2026-39640 | CRITICAL | 9.6 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This iss... |
| CVE-2026-39620 | CRITICAL | 9.6 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to ... |
| CVE-2026-39619 | CRITICAL | 9.6 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web ... |
| CVE-2026-39617 | CRITICAL | 9.6 | 0.1% | Apr 8, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forge... |
| CVE-2026-33088 | CRITICAL | 9.8 | 0.3% | Apr 8, 2026 | Movable Type provided by Six Apart Ltd. contains an SQL Injection vulnerability which may allow an attacker to execute a... |
| CVE-2026-25776 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute a... |
| CVE-2026-3535 | CRITICAL | 9.8 | 0.9% | Apr 8, 2026 | The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type val... |
| CVE-2026-4003 | CRITICAL | 9.8 | 0.9% | Apr 8, 2026 | The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all ... |
| CVE-2026-3296 | CRITICAL | 9.8 | 3.5% | Apr 8, 2026 | The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3... |
| CVE-2026-27143 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the comp... |
| CVE-2026-39846 | CRITICAL | 9 | 0.5% | Apr 7, 2026 | SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger re... |
| CVE-2026-34582 | CRITICAL | 9.1 | 0.2% | Apr 7, 2026 | Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records... |
| CVE-2026-34078 | CRITICAL | 10 | 1.7% | Apr 7, 2026 | Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths ... |
| CVE-2026-31789 | CRITICAL | 9.8 | 0.2% | Apr 7, 2026 | Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflo... |
| CVE-2026-39397 | CRITICAL | 9.8 | 0.4% | Apr 7, 2026 | @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/... |
| CVE-2026-34045 | CRITICAL | 9.1 | 0.5% | Apr 7, 2026 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP... |
| CVE-2026-33439 | CRITICAL | 9.8 | 10.5% | Apr 7, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulner... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now