2026 CVE Vulnerabilities
65,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40308 | HIGH | 8.8 | 0.9% | Apr 16, 2026 | My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJA... |
| CVE-2026-40249 | MEDIUM | 5.3 | 0.3% | Apr 16, 2026 | free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT... |
| CVE-2026-40248 | HIGH | 7.5 | 0.4% | Apr 16, 2026 | free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han... |
| CVE-2026-40247 | HIGH | 7.5 | 0.5% | Apr 16, 2026 | free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han... |
| CVE-2026-40246 | HIGH | 7.5 | 0.4% | Apr 16, 2026 | free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the han... |
| CVE-2026-40170 | HIGH | 7.5 | 0.8% | Apr 16, 2026 | ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transpor... |
| CVE-2026-39313 | HIGH | 8.7 | 0.5% | Apr 16, 2026 | mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRe... |
| CVE-2026-35469 | MEDIUM | 6.5 | 0.7% | Apr 16, 2026 | spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame... |
| CVE-2026-34164 | MEDIUM | 4.9 | 0.4% | Apr 16, 2026 | Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingSer... |
| CVE-2026-33472 | MEDIUM | 4.8 | 0.1% | Apr 16, 2026 | Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw... |
| CVE-2026-40901 | HIGH | 8.8 | 0.6% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocit... |
| CVE-2026-40900 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-40899 | MEDIUM | 6.5 | 0.4% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC paramete... |
| CVE-2026-33207 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-33122 | CRITICAL | 9.8 | 0.4% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-6442 | HIGH | 8.3 | 0.4% | Apr 16, 2026 | Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands t... |
| CVE-2026-33121 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-33084 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-41082 | HIGH | 7.8 | 0.2% | Apr 16, 2026 | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. |
| CVE-2026-33083 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-33082 | CRITICAL | 9.8 | 0.3% | Apr 16, 2026 | DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerab... |
| CVE-2026-2336 | HIGH | 8.8 | 0.2% | Apr 16, 2026 | A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared ... |
| CVE-2026-27820 | CRITICAL | 9.8 | 0.6% | Apr 16, 2026 | zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 a... |
| CVE-2026-24749 | MEDIUM | 5.3 | 0.4% | Apr 16, 2026 | The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-r... |
| CVE-2026-41080 | LOW | 2.9 | 0.4% | Apr 16, 2026 | libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now