2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31370 | MEDIUM | 6.3 | 0.2% | Apr 21, 2026 | Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect serv... |
| CVE-2026-31369 | LOW | 3.2 | 0.1% | Apr 21, 2026 | PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availab... |
| CVE-2026-31368 | HIGH | 7.8 | 0.1% | Apr 21, 2026 | AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service avail... |
| CVE-2026-5965 | CRITICAL | 9.8 | 1.7% | Apr 21, 2026 | NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to in... |
| CVE-2026-6675 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Em... |
| CVE-2026-6674 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter... |
| CVE-2026-40497 | HIGH | 8.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDanger... |
| CVE-2026-6058 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 fi... |
| CVE-2026-40496 | CRITICAL | 9.1 | 0.4% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are g... |
| CVE-2026-40250 | HIGH | 7.1 | 0.4% | Apr 21, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-40244 | HIGH | 7.1 | 0.4% | Apr 21, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-39973 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability... |
| CVE-2026-39886 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-39866 | HIGH | 8.8 | 2.3% | Apr 21, 2026 | Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command... |
| CVE-2026-40264 | LOW | 2.7 | 0.3% | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation... |
| CVE-2026-39946 | MEDIUM | 4.9 | 0.2% | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privile... |
| CVE-2026-39861 | CRITICAL | 10 | 0.5% | Apr 21, 2026 | Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processe... |
| CVE-2026-39396 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` i... |
| CVE-2026-39388 | LOW | 3.1 | 0.1% | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authen... |
| CVE-2026-39386 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t... |
| CVE-2026-39378 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versi... |
| CVE-2026-39377 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions... |
| CVE-2026-39320 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to... |
| CVE-2026-41331 | MEDIUM | 6.9 | 0.3% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that a... |
| CVE-2026-41330 | MEDIUM | 4.4 | 0.1% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to prop... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now