2026 CVE Vulnerabilities
65,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40515 | MEDIUM | 5.5 | 0.2% | Apr 17, 2026 | OpenHarness before commit bd4df81 contains a permission bypass vulnerability that allows attackers to read sensitive fil... |
| CVE-2026-3464 | HIGH | 8.8 | 1.0% | Apr 17, 2026 | The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat... |
| CVE-2026-21733 | HIGH | 7.3 | 0.1% | Apr 17, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re... |
| CVE-2026-6497 | MEDIUM | 6.3 | 0.3% | Apr 17, 2026 | A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown fu... |
| CVE-2026-6284 | CRITICAL | 9.3 | 0.4% | Apr 17, 2026 | An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to syst... |
| CVE-2026-21709 | MEDIUM | 6.7 | 0.2% | Apr 17, 2026 | A vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement. |
| CVE-2026-6496 | MEDIUM | 5.4 | 0.5% | Apr 17, 2026 | A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /fileman... |
| CVE-2026-6493 | LOW | 3.5 | 0.3% | Apr 17, 2026 | A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[lo... |
| CVE-2026-41153 | CRITICAL | 9.8 | 0.3% | Apr 17, 2026 | In JetBrains Junie before 252.549.29 command execution was possible via malicious project file |
| CVE-2026-37749 | CRITICAL | 9.8 | 0.7% | Apr 17, 2026 | A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attack... |
| CVE-2026-6492 | MEDIUM | 5.5 | 0.4% | Apr 17, 2026 | A vulnerability was detected in arnobt78 Hotel Booking Management System up to f8922d0e0f6ac1cc761974c7616f44c2bbc04bea.... |
| CVE-2026-6491 | MEDIUM | 5.3 | 0.2% | Apr 17, 2026 | A security vulnerability has been detected in libvips up to 8.18.2. The affected element is the function im_minpos_vec o... |
| CVE-2026-6490 | HIGH | 7.3 | 0.3% | Apr 17, 2026 | A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown f... |
| CVE-2026-40459 | HIGH | 8.8 | 0.6% | Apr 17, 2026 | PAC4J is vulnerable to LDAP Injection in multiple methods. A low-privileged remote attacker can inject crafted LDAP synt... |
| CVE-2026-40458 | MEDIUM | 6.5 | 0.2% | Apr 17, 2026 | PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website wh... |
| CVE-2026-31317 | HIGH | 7.5 | 0.5% | Apr 17, 2026 | Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitr... |
| CVE-2026-6507 | HIGH | 7.5 | 0.5% | Apr 17, 2026 | A flaw was found in dnsmasq. A remote attacker could exploit an out-of-bounds write vulnerability by sending a specially... |
| CVE-2026-6489 | MEDIUM | 6.3 | 0.3% | Apr 17, 2026 | A security flaw has been discovered in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This issue affects ... |
| CVE-2026-6488 | MEDIUM | 6.3 | 0.2% | Apr 17, 2026 | A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affec... |
| CVE-2026-6487 | MEDIUM | 4.3 | 0.4% | Apr 17, 2026 | A flaw has been found in Qihui jtbc5 CMS 5.0.3.6. Affected is an unknown function of the file /dev/code/common/diplomat/... |
| CVE-2026-6486 | LOW | 3.5 | 0.2% | Apr 17, 2026 | A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/app... |
| CVE-2026-28263 | MEDIUM | 4.8 | 0.2% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-23777 | MEDIUM | 6.5 | 0.3% | Apr 17, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-6483 | HIGH | 7.3 | 14.1% | Apr 17, 2026 | A vulnerability was found in Wavlink WL-WN530H4 20220721. This vulnerability affects the function strcat/snprintf of the... |
| CVE-2026-5131 | MEDIUM | 6.9 | 0.4% | Apr 17, 2026 | GREENmod uses named pipes for communication between plugins, the web portal, and the system service, but the access cont... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now