2026 CVE Vulnerabilities
65,045 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40480 | HIGH | 7.1 | 0.3% | Apr 18, 2026 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoin... |
| CVE-2026-40349 | HIGH | 8.8 | 0.5% | Apr 18, 2026 | Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti... |
| CVE-2026-40348 | HIGH | 7.7 | 0.4% | Apr 18, 2026 | Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti... |
| CVE-2026-40347 | MEDIUM | 5.3 | 0.4% | Apr 18, 2026 | Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerabi... |
| CVE-2026-40346 | MEDIUM | 6.5 | 0.4% | Apr 18, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-40341 | LOW | 3.5 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_u... |
| CVE-2026-40340 | MEDIUM | 6.1 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulner... |
| CVE-2026-40339 | MEDIUM | 5.2 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt... |
| CVE-2026-40338 | MEDIUM | 5.2 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the... |
| CVE-2026-40337 | MEDIUM | 5.1 | 0.2% | Apr 18, 2026 | The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given ... |
| CVE-2026-40336 | LOW | 2.4 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack... |
| CVE-2026-40335 | MEDIUM | 5.2 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt... |
| CVE-2026-40334 | LOW | 3.5 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exi... |
| CVE-2026-40333 | MEDIUM | 6.1 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2... |
| CVE-2026-40324 | CRITICAL | 9.1 | 0.9% | Apr 18, 2026 | Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's... |
| CVE-2026-40323 | HIGH | 7.5 | 0.2% | Apr 18, 2026 | SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architectu... |
| CVE-2026-2262 | HIGH | 7.5 | 2.4% | Apr 18, 2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2026-5250 | — | — | — | Apr 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-40486 | MEDIUM | 4.3 | 0.3% | Apr 17, 2026 | Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATC... |
| CVE-2026-40481 | HIGH | 7.5 | 0.4% | Apr 17, 2026 | monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoi... |
| CVE-2026-40479 | MEDIUM | 5.4 | 0.2% | Apr 17, 2026 | Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in Ki... |
| CVE-2026-2434 | MEDIUM | 6.4 | 0.2% | Apr 17, 2026 | The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute... |
| CVE-2026-5720 | CRITICAL | 9.1 | 0.7% | Apr 17, 2026 | miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause... |
| CVE-2026-40478 | CRITICAL | 9 | 0.8% | Apr 17, 2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co... |
| CVE-2026-40477 | CRITICAL | 9 | 0.9% | Apr 17, 2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now