2026 CVE Vulnerabilities
65,045 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40045 | MEDIUM | 5.9 | 0.1% | Apr 21, 2026 | OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials... |
| CVE-2026-35588 | MEDIUM | 6.3 | 0.2% | Apr 21, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`g... |
| CVE-2026-35587 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (... |
| CVE-2026-35570 | HIGH | 8.4 | 0.2% | Apr 21, 2026 | OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to ... |
| CVE-2026-34839 | MEDIUM | 6.5 | 0.4% | Apr 21, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes ... |
| CVE-2026-5721 | MEDIUM | 4.7 | 0.3% | Apr 20, 2026 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stor... |
| CVE-2026-34082 | MEDIUM | 4.3 | 0.2% | Apr 20, 2026 | Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<ap... |
| CVE-2026-6729 | HIGH | 7.6 | 0.2% | Apr 20, 2026 | HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated... |
| CVE-2026-29643 | HIGH | 7.1 | 0.2% | Apr 20, 2026 | XiangShan (Open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) c... |
| CVE-2026-22051 | MEDIUM | 4.3 | 0.2% | Apr 20, 2026 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Di... |
| CVE-2026-0930 | MEDIUM | 4.3 | 0.2% | Apr 20, 2026 | Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated us... |
| CVE-2026-5928 | HIGH | 7.5 | 0.3% | Apr 20, 2026 | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between ... |
| CVE-2026-5450 | CRITICAL | 9.8 | 0.5% | Apr 20, 2026 | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version ... |
| CVE-2026-5358 | — | — | — | Apr 20, 2026 | Rejected reason: REJECTED: CVE-2026-5358 is rejected for two reasons. Firstly it has been discovered that no NIS+ client... |
| CVE-2026-4852 | MEDIUM | 6.4 | 0.2% | Apr 20, 2026 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2026-34403 | HIGH | 8.1 | 0.2% | Apr 20, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui u... |
| CVE-2026-33626 | HIGH | 7.5 | 45.3% | Apr 20, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Ser... |
| CVE-2026-33432 | CRITICAL | 9.1 | 0.4% | Apr 20, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8... |
| CVE-2026-33431 | MEDIUM | 6.5 | 0.4% | Apr 20, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS... |
| CVE-2026-33031 | HIGH | 8.1 | 0.3% | Apr 20, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis... |
| CVE-2026-32613 | CRITICAL | 9.9 | 0.6% | Apr 20, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring ... |
| CVE-2026-32604 | CRITICAL | 9.9 | 0.6% | Apr 20, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2... |
| CVE-2026-29648 | HIGH | 8.8 | 0.3% | Apr 20, 2026 | In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcf... |
| CVE-2026-29647 | MEDIUM | 6.5 | 0.2% | Apr 20, 2026 | In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state ... |
| CVE-2026-29646 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now