2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38940 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code ... |
| CVE-2026-38939 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code... |
| CVE-2026-36960 | HIGH | 8.8 | 0.2% | Apr 30, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.... |
| CVE-2026-36759 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticat... |
| CVE-2026-36758 | MEDIUM | 4.3 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated at... |
| CVE-2026-36756 | MEDIUM | 5.4 | 0.1% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated a... |
| CVE-2026-36340 | HIGH | 8.1 | 0.6% | Apr 30, 2026 | An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose e... |
| CVE-2026-34998 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-34997 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-34996 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-34995 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-34994 | — | — | — | Apr 30, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2026-7500 | MEDIUM | 5.4 | 0.2% | Apr 30, 2026 | When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled... |
| CVE-2026-36959 | HIGH | 7.5 | 0.4% | Apr 30, 2026 | U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. T... |
| CVE-2026-36958 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concur... |
| CVE-2026-36957 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI h... |
| CVE-2026-36956 | HIGH | 8.8 | 0.2% | Apr 30, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireles... |
| CVE-2026-7246 | HIGH | 7.2 | 0.9% | Apr 30, 2026 | This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Clic... |
| CVE-2026-7163 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Mul... |
| CVE-2026-2892 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including... |
| CVE-2026-7402 | HIGH | 8.1 | 0.4% | Apr 30, 2026 | Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This ... |
| CVE-2026-7399 | HIGH | 8.1 | 0.3% | Apr 30, 2026 | Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege... |
| CVE-2026-7382 | MEDIUM | 6.5 | 0.3% | Apr 30, 2026 | Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized ... |
| CVE-2026-5080 | MEDIUM | 5.9 | 0.4% | Apr 30, 2026 | Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generate... |
| CVE-2026-41882 | HIGH | 7.5 | 0.4% | Apr 30, 2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now