2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33448 | LOW | 3.3 | 0.1% | Apr 30, 2026 | CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.... |
| CVE-2026-33447 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers... |
| CVE-2026-33446 | CRITICAL | 9.8 | 0.3% | Apr 30, 2026 | CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attack... |
| CVE-2026-7461 | HIGH | 7.5 | 0.5% | Apr 30, 2026 | Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amaz... |
| CVE-2026-40904 | HIGH | 8.1 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-40603 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-40601 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-40600 | HIGH | 8.1 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-40595 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-35514 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-32148 | MEDIUM | 5.9 | 0.2% | Apr 30, 2026 | Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency... |
| CVE-2026-3833 | HIGH | 7.4 | 0.9% | Apr 30, 2026 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstra... |
| CVE-2026-3832 | LOW | 3.7 | 0.7% | Apr 30, 2026 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online ... |
| CVE-2026-36766 | MEDIUM | 5.4 | 0.1% | Apr 30, 2026 | Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer ... |
| CVE-2026-36765 | HIGH | 8.8 | 0.3% | Apr 30, 2026 | An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticat... |
| CVE-2026-36763 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 al... |
| CVE-2026-36762 | HIGH | 8.8 | 0.4% | Apr 30, 2026 | An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers ... |
| CVE-2026-36761 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers... |
| CVE-2026-33845 | CRITICAL | 9.1 | 0.8% | Apr 30, 2026 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an i... |
| CVE-2026-36767 | CRITICAL | 10 | 0.4% | Apr 30, 2026 | A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary f... |
| CVE-2026-36764 | MEDIUM | 5 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows aut... |
| CVE-2026-36760 | CRITICAL | 9.6 | 0.4% | Apr 30, 2026 | An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with ... |
| CVE-2026-36757 | MEDIUM | 4.3 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authentica... |
| CVE-2026-5174 | HIGH | 8.8 | 3.2% | Apr 30, 2026 | Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue ... |
| CVE-2026-4670 | CRITICAL | 9.8 | 5.6% | Apr 30, 2026 | Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Byp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now