2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5358 | — | — | — | Apr 20, 2026 | Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client... |
| CVE-2026-4852 | MEDIUM | 6.4 | 0.2% | Apr 20, 2026 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2026-34403 | HIGH | 8.1 | 0.2% | Apr 20, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui u... |
| CVE-2026-33626 | HIGH | 7.5 | 45.3% | Apr 20, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Ser... |
| CVE-2026-33432 | CRITICAL | 9.1 | 0.4% | Apr 20, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8... |
| CVE-2026-33431 | MEDIUM | 6.5 | 0.4% | Apr 20, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS... |
| CVE-2026-33031 | HIGH | 8.1 | 0.3% | Apr 20, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis... |
| CVE-2026-32613 | CRITICAL | 9.9 | 0.6% | Apr 20, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring ... |
| CVE-2026-32604 | CRITICAL | 9.9 | 0.6% | Apr 20, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2... |
| CVE-2026-29648 | HIGH | 8.8 | 0.3% | Apr 20, 2026 | In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcf... |
| CVE-2026-29647 | MEDIUM | 6.5 | 0.2% | Apr 20, 2026 | In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state ... |
| CVE-2026-29646 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to t... |
| CVE-2026-29642 | HIGH | 7.8 | 0.1% | Apr 20, 2026 | A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted ... |
| CVE-2026-6550 | MEDIUM | 5.7 | 0.1% | Apr 20, 2026 | Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and ... |
| CVE-2026-6257 | CRITICAL | 9.2 | 0.6% | Apr 20, 2026 | Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing ... |
| CVE-2026-6249 | HIGH | 8.8 | 0.6% | Apr 20, 2026 | Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a... |
| CVE-2026-5478 | HIGH | 8.1 | 1.0% | Apr 20, 2026 | The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl... |
| CVE-2026-32311 | CRITICAL | 9.8 | 0.5% | Apr 20, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-32135 | HIGH | 7.5 | 0.5% | Apr 20, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggera... |
| CVE-2026-29649 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related f... |
| CVE-2026-29645 | HIGH | 7.5 | 0.5% | Apr 20, 2026 | NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)... |
| CVE-2026-6248 | HIGH | 8.1 | 0.6% | Apr 20, 2026 | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th... |
| CVE-2026-6060 | MEDIUM | 4.5 | 0.2% | Apr 20, 2026 | A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a... |
| CVE-2026-41389 | MEDIUM | 6.3 | 0.3% | Apr 20, 2026 | OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing ... |
| CVE-2026-39112 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now