2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5141 | HIGH | 8.8 | 0.2% | Apr 29, 2026 | Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM S... |
| CVE-2026-41952 | HIGH | 7.8 | 0.1% | Apr 29, 2026 | Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP... |
| CVE-2026-41220 | HIGH | 7.8 | 0.1% | Apr 29, 2026 | Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP... |
| CVE-2026-38992 | CRITICAL | 9.8 | 0.4% | Apr 29, 2026 | Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints... |
| CVE-2026-36841 | CRITICAL | 9.8 | 1.1% | Apr 29, 2026 | TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in ... |
| CVE-2026-36837 | HIGH | 7.5 | 0.3% | Apr 29, 2026 | TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname pa... |
| CVE-2026-25852 | MEDIUM | 6.7 | 0.1% | Apr 29, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D... |
| CVE-2026-5140 | HIGH | 8.8 | 0.5% | Apr 29, 2026 | Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Resea... |
| CVE-2026-42525 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL... |
| CVE-2026-42524 | HIGH | 8 | 0.3% | Apr 29, 2026 | Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in ... |
| CVE-2026-42523 | CRITICAL | 9 | 0.3% | Apr 29, 2026 | Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing val... |
| CVE-2026-42522 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers wi... |
| CVE-2026-42521 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructor... |
| CVE-2026-42520 | HIGH | 7.5 | 0.4% | Apr 29, 2026 | Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file cre... |
| CVE-2026-42519 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overa... |
| CVE-2026-42652 | HIGH | 7.1 | 0.1% | Apr 29, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Reg... |
| CVE-2026-42648 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrec... |
| CVE-2026-42646 | HIGH | 7.6 | 0.2% | Apr 29, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPr... |
| CVE-2026-42645 | MEDIUM | 4.3 | 0.1% | Apr 29, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Or... |
| CVE-2026-42644 | MEDIUM | 5.3 | 0.2% | Apr 29, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPDeveloper BetterDocs bette... |
| CVE-2026-42643 | MEDIUM | 5.9 | 0.1% | Apr 29, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP Image Wi... |
| CVE-2026-42642 | MEDIUM | 5.3 | 0.2% | Apr 29, 2026 | Missing Authorization vulnerability in StellarWP GiveWP give allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-42641 | MEDIUM | 5.4 | 0.1% | Apr 29, 2026 | Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request F... |
| CVE-2026-42249 | CRITICAL | 9.8 | 0.6% | Apr 29, 2026 | Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of at... |
| CVE-2026-42248 | CRITICAL | 9.8 | 0.4% | Apr 29, 2026 | Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike othe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now