2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22011 | HIGH | 7.6 | 0.3% | Apr 21, 2026 | Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported version... |
| CVE-2026-22010 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic... |
| CVE-2026-22009 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2026-22008 | LOW | 3.7 | 0.2% | Apr 21, 2026 | Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0... |
| CVE-2026-22007 | LOW | 2.9 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-22006 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapsho... |
| CVE-2026-22005 | MEDIUM | 4.9 | 0.3% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2026-22004 | MEDIUM | 4.9 | 0.3% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are... |
| CVE-2026-22003 | MEDIUM | 6 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). ... |
| CVE-2026-22002 | MEDIUM | 4.9 | 0.3% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2026-22001 | LOW | 2.7 | 0.3% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t... |
| CVE-2026-21999 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-... |
| CVE-2026-21998 | MEDIUM | 4.9 | 0.3% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2026-21997 | HIGH | 8.5 | 0.2% | Apr 21, 2026 | Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common... |
| CVE-2026-6819 | HIGH | 8.8 | 0.3% | Apr 21, 2026 | HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enab... |
| CVE-2026-41320 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a special... |
| CVE-2026-40909 | MEDIUM | 6.5 | 0.7% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) c... |
| CVE-2026-40908 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root execut... |
| CVE-2026-40907 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/... |
| CVE-2026-40903 | CRITICAL | 9.1 | 0.2% | Apr 21, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can ... |
| CVE-2026-40890 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing... |
| CVE-2026-40889 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authentica... |
| CVE-2026-40888 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authent... |
| CVE-2026-40887 | CRITICAL | 9.1 | 1.8% | Apr 21, 2026 | Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and ... |
| CVE-2026-40885 | HIGH | 8.8 | 0.3% | Apr 21, 2026 | goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials thr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now