2026 CVE Vulnerabilities
65,045 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6629 | HIGH | 7.3 | 0.3% | Apr 20, 2026 | A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.e... |
| CVE-2026-6628 | MEDIUM | 6.3 | 0.2% | Apr 20, 2026 | A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query... |
| CVE-2026-6626 | MEDIUM | 6.3 | 0.2% | Apr 20, 2026 | A vulnerability was detected in Cockpit-HQ Cockpit up to 2.13.5. Affected by this issue is some unknown functionality of... |
| CVE-2026-6625 | HIGH | 7.3 | 0.3% | Apr 20, 2026 | A security vulnerability has been detected in moxi624 Mogu Blog v2 up to 5.2. Affected by this vulnerability is the func... |
| CVE-2026-6624 | LOW | 2.4 | 0.2% | Apr 20, 2026 | A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the fil... |
| CVE-2026-6623 | MEDIUM | 4.8 | 0.2% | Apr 20, 2026 | A security flaw has been discovered in BichitroGan ISP Billing Software 2025.3.20. This impacts an unknown function of t... |
| CVE-2026-6622 | LOW | 2.4 | 0.2% | Apr 20, 2026 | A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the fi... |
| CVE-2026-31430 | HIGH | 7.1 | 0.1% | Apr 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access when parsing extens... |
| CVE-2026-31429 | MEDIUM | 5.5 | 0.3% | Apr 20, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skb: fix cross-cache free of KFENCE-allocated ... |
| CVE-2026-6621 | HIGH | 7.3 | 0.3% | Apr 20, 2026 | A vulnerability was determined in 1024bit extend-deep up to 0.1.6. The impacted element is an unknown function of the fi... |
| CVE-2026-6620 | MEDIUM | 6.3 | 0.3% | Apr 20, 2026 | A vulnerability was found in SonicCloudOrg sonic-server up to 2.0.0. The affected element is the function Upload of the ... |
| CVE-2026-6619 | LOW | 3.5 | 0.2% | Apr 20, 2026 | A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/ap... |
| CVE-2026-6618 | MEDIUM | 6.3 | 0.2% | Apr 20, 2026 | A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_... |
| CVE-2026-5967 | HIGH | 8.8 | 0.4% | Apr 20, 2026 | ThreatSonar Anti-Ransomware developed by TeamT5 has an Privilege Escalation vulnerability. Authenticated remote attacker... |
| CVE-2026-39454 | HIGH | 8.5 | 0.1% | Apr 20, 2026 | SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file a... |
| CVE-2026-6617 | MEDIUM | 6.3 | 0.2% | Apr 20, 2026 | A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provid... |
| CVE-2026-6616 | MEDIUM | 6.3 | 0.2% | Apr 20, 2026 | A security vulnerability has been detected in TransformerOptimus SuperAGI up to 0.0.14. This affects the function extrac... |
| CVE-2026-6615 | HIGH | 7.3 | 0.5% | Apr 20, 2026 | A weakness has been identified in TransformerOptimus SuperAGI up to 0.0.14. Affected by this issue is the function Uploa... |
| CVE-2026-5966 | HIGH | 8.1 | 0.4% | Apr 20, 2026 | ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attac... |
| CVE-2026-5964 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to injec... |
| CVE-2026-5963 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to injec... |
| CVE-2026-41282 | HIGH | 7.5 | 0.3% | Apr 20, 2026 | ProjectDiscovery Nuclei 3 before 3.8.0 allows DSL expression injection. This affects use of -env-vars for multi-step tem... |
| CVE-2026-6644 | CRITICAL | 9.1 | 1.5% | Apr 20, 2026 | A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an administrati... |
| CVE-2026-6643 | CRITICAL | 9.9 | 0.5% | Apr 20, 2026 | A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of unb... |
| CVE-2026-6614 | MEDIUM | 6.3 | 0.2% | Apr 20, 2026 | A security flaw has been discovered in TransformerOptimus SuperAGI up to 0.0.14. Affected by this vulnerability is the f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now