2026 CVE Vulnerabilities
65,045 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6573 | MEDIUM | 6.3 | 0.3% | Apr 19, 2026 | A vulnerability was detected in PHPEMS 11.0. This affects the function temppage of the file /app/exam/controller/exams.m... |
| CVE-2026-6572 | MEDIUM | 5.6 | 0.3% | Apr 19, 2026 | A security vulnerability has been detected in Collabora KodExplorer up to 4.52. Affected by this issue is some unknown f... |
| CVE-2026-6571 | MEDIUM | 6.3 | 0.3% | Apr 19, 2026 | A weakness has been identified in kodcloud KodExplorer up to 4.52. Affected by this vulnerability is the function roleGr... |
| CVE-2026-6570 | LOW | 2.7 | 0.3% | Apr 19, 2026 | A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file... |
| CVE-2026-6569 | HIGH | 7.3 | 0.4% | Apr 19, 2026 | A vulnerability was identified in kodcloud KodExplorer up to 4.52. This impacts the function fileGet of the file /app/co... |
| CVE-2026-6568 | HIGH | 7.3 | 0.5% | Apr 19, 2026 | A vulnerability was determined in kodcloud KodExplorer up to 4.52. This affects the function share.class.php::initShareO... |
| CVE-2026-6564 | MEDIUM | 4.3 | 0.3% | Apr 19, 2026 | A vulnerability was found in EMQ EMQX Enterprise up to 6.1.0. The impacted element is an unknown function of the compone... |
| CVE-2026-6563 | HIGH | 8.8 | 0.5% | Apr 19, 2026 | A vulnerability has been found in H3C Magic B1 up to 100R004. The affected element is the function SetAPWifiorLedInfoByI... |
| CVE-2026-6562 | HIGH | 7.3 | 0.3% | Apr 19, 2026 | A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Sear... |
| CVE-2026-6561 | MEDIUM | 4.7 | 0.3% | Apr 19, 2026 | A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file applicat... |
| CVE-2026-6560 | HIGH | 8.8 | 0.5% | Apr 19, 2026 | A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_B... |
| CVE-2026-6559 | MEDIUM | 5.3 | 0.3% | Apr 19, 2026 | A weakness has been identified in Wavlink WL-WN579A3 220323. This affects the function sub_401F80 of the file /cgi-bin/l... |
| CVE-2026-0868 | MEDIUM | 6.4 | 0.2% | Apr 19, 2026 | The EMC – Easily Embed Calendly Scheduling Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-6056 | — | — | — | Apr 18, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-41242 | CRITICAL | 9.8 | 0.8% | Apr 18, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers... |
| CVE-2026-40948 | MEDIUM | 5.4 | 0.3% | Apr 18, 2026 | The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `s... |
| CVE-2026-2986 | MEDIUM | 6.4 | 0.3% | Apr 18, 2026 | The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes... |
| CVE-2026-2505 | MEDIUM | 5.4 | 0.2% | Apr 18, 2026 | The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including... |
| CVE-2026-0894 | MEDIUM | 6.4 | 0.2% | Apr 18, 2026 | The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2026-41254 | HIGH | 7.5 | 0.4% | Apr 18, 2026 | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed ... |
| CVE-2026-32690 | LOW | 3.7 | 0.4% | Apr 18, 2026 | Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by th... |
| CVE-2026-32228 | HIGH | 7.5 | 0.4% | Apr 18, 2026 | UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate t... |
| CVE-2026-30912 | HIGH | 7.5 | 0.4% | Apr 18, 2026 | In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to f... |
| CVE-2026-30898 | HIGH | 8.8 | 0.8% | Apr 18, 2026 | An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause ... |
| CVE-2026-25917 | HIGH | 7.2 | 0.8% | Apr 18, 2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now