2026 CVE Vulnerabilities
65,045 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40098 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-35154 | MEDIUM | 6.7 | 0.1% | Apr 20, 2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers... |
| CVE-2026-30269 | CRITICAL | 9.9 | 0.3% | Apr 20, 2026 | Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a... |
| CVE-2026-30266 | HIGH | 7.8 | 0.1% | Apr 20, 2026 | Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbit... |
| CVE-2026-28684 | MEDIUM | 6.6 | 0.2% | Apr 20, 2026 | python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, ... |
| CVE-2026-26951 | MEDIUM | 6.7 | 0.1% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-26943 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-26942 | HIGH | 7.2 | 0.9% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i... |
| CVE-2026-25525 | MEDIUM | 4.9 | 0.5% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-25524 | HIGH | 8.1 | 0.5% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-24506 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-24505 | HIGH | 7.2 | 0.4% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privi... |
| CVE-2026-24504 | HIGH | 7.2 | 0.4% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-22761 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att... |
| CVE-2026-6652 | MEDIUM | 4.7 | 0.2% | Apr 20, 2026 | A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/mod... |
| CVE-2026-6651 | LOW | 2.4 | 0.2% | Apr 20, 2026 | A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of ... |
| CVE-2026-6650 | MEDIUM | 4.7 | 0.2% | Apr 20, 2026 | A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/Ap... |
| CVE-2026-6066 | HIGH | 7.1 | 0.1% | Apr 20, 2026 | ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automa... |
| CVE-2026-41245 | HIGH | 7.5 | 0.3% | Apr 20, 2026 | Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFold... |
| CVE-2026-40896 | HIGH | 7.1 | 0.2% | Apr 20, 2026 | OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas`... |
| CVE-2026-3219 | MEDIUM | 4.6 | 0.1% | Apr 20, 2026 | pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP f... |
| CVE-2026-39918 | CRITICAL | 9.8 | 0.7% | Apr 20, 2026 | Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parame... |
| CVE-2026-34429 | MEDIUM | 5.4 | 0.3% | Apr 20, 2026 | Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media u... |
| CVE-2026-34428 | HIGH | 8.3 | 0.3% | Apr 20, 2026 | Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/edit... |
| CVE-2026-34427 | HIGH | 8.8 | 0.6% | Apr 20, 2026 | Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now