2026 CVE Vulnerabilities
65,045 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29642 | HIGH | 7.8 | 0.1% | Apr 20, 2026 | A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted ... |
| CVE-2026-6550 | MEDIUM | 5.7 | 0.1% | Apr 20, 2026 | Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and ... |
| CVE-2026-6257 | CRITICAL | 9.2 | 0.6% | Apr 20, 2026 | Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing ... |
| CVE-2026-6249 | HIGH | 8.8 | 0.6% | Apr 20, 2026 | Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a... |
| CVE-2026-5478 | HIGH | 8.1 | 1.0% | Apr 20, 2026 | The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl... |
| CVE-2026-32311 | CRITICAL | 9.8 | 0.5% | Apr 20, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-32135 | HIGH | 7.5 | 0.5% | Apr 20, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggera... |
| CVE-2026-29649 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related f... |
| CVE-2026-29645 | HIGH | 7.5 | 0.5% | Apr 20, 2026 | NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)... |
| CVE-2026-6248 | HIGH | 8.1 | 0.6% | Apr 20, 2026 | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th... |
| CVE-2026-6060 | MEDIUM | 4.5 | 0.2% | Apr 20, 2026 | A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a... |
| CVE-2026-41389 | MEDIUM | 6.3 | 0.3% | Apr 20, 2026 | OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing ... |
| CVE-2026-39112 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in ... |
| CVE-2026-39111 | HIGH | 7.5 | 0.3% | Apr 20, 2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the ema... |
| CVE-2026-39110 | HIGH | 8.2 | 0.3% | Apr 20, 2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con... |
| CVE-2026-39109 | CRITICAL | 9.4 | 0.3% | Apr 20, 2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the... |
| CVE-2026-26399 | MEDIUM | 5.3 | 0.2% | Apr 20, 2026 | A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function... |
| CVE-2026-23758 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows ... |
| CVE-2026-23757 | MEDIUM | 5.4 | 0.1% | Apr 20, 2026 | GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title p... |
| CVE-2026-23756 | MEDIUM | 5.4 | 0.1% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the s... |
| CVE-2026-23753 | MEDIUM | 4.8 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality... |
| CVE-2026-23752 | MEDIUM | 4.8 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editi... |
| CVE-2026-6662 | HIGH | 7.3 | 0.2% | Apr 20, 2026 | A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src... |
| CVE-2026-41445 | HIGH | 8.8 | 0.3% | Apr 20, 2026 | KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft... |
| CVE-2026-40488 | HIGH | 8.8 | 0.7% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now