2026 CVE Vulnerabilities
65,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34232 | HIGH | 7.5 | 0.5% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_... |
| CVE-2026-33569 | MEDIUM | 6.5 | 0.2% | Apr 17, 2026 | Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and ses... |
| CVE-2026-33516 | CRITICAL | 9.1 | 0.4% | Apr 17, 2026 | xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP ca... |
| CVE-2026-33093 | MEDIUM | 5.3 | 0.2% | Apr 17, 2026 | Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing c... |
| CVE-2026-32650 | HIGH | 7.5 | 0.2% | Apr 17, 2026 | Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing da... |
| CVE-2026-32648 | MEDIUM | 5.3 | 0.2% | Apr 17, 2026 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/R... |
| CVE-2026-32624 | MEDIUM | 6.5 | 0.4% | Apr 17, 2026 | xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its log... |
| CVE-2026-32623 | HIGH | 8.1 | 0.5% | Apr 17, 2026 | xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the Neu... |
| CVE-2026-32324 | HIGH | 7.7 | 0.1% | Apr 17, 2026 | Anviz CX7 Firmware is vulnerable because the application embeds reusable certificate/key material, enabling decryption... |
| CVE-2026-32107 | HIGH | 8.8 | 0.2% | Apr 17, 2026 | xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle a... |
| CVE-2026-32105 | HIGH | 7.7 | 0.2% | Apr 17, 2026 | xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Auth... |
| CVE-2026-31927 | MEDIUM | 4.9 | 0.4% | Apr 17, 2026 | Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files... |
| CVE-2026-6437 | MEDIUM | 6.9 | 0.4% | Apr 17, 2026 | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-drive... |
| CVE-2026-40525 | CRITICAL | 9.1 | 0.6% | Apr 17, 2026 | OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route su... |
| CVE-2026-33337 | HIGH | 7.5 | 0.5% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when des... |
| CVE-2026-28224 | HIGH | 8.2 | 0.5% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the... |
| CVE-2026-28214 | MEDIUM | 6.5 | 1.1% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the Clum... |
| CVE-2026-28212 | HIGH | 7.5 | 0.5% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, w... |
| CVE-2026-27890 | HIGH | 8.2 | 0.5% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when pro... |
| CVE-2026-5718 | HIGH | 8.1 | 4.2% | Apr 17, 2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in... |
| CVE-2026-5710 | HIGH | 7.5 | 0.7% | Apr 17, 2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t... |
| CVE-2026-40320 | HIGH | 7.8 | 0.1% | Apr 17, 2026 | Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rende... |
| CVE-2026-40319 | MEDIUM | 5.5 | 0.1% | Apr 17, 2026 | Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes ... |
| CVE-2026-40518 | CRITICAL | 9.1 | 0.4% | Apr 17, 2026 | ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-m... |
| CVE-2026-40516 | MEDIUM | 6.3 | 0.2% | Apr 17, 2026 | OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now