2026 CVE Vulnerabilities
65,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5426 | CRITICAL | 9.1 | 1.0% | Apr 16, 2026 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 all... |
| CVE-2026-37100 | MEDIUM | 6.5 | 0.3% | Apr 16, 2026 | An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: ... |
| CVE-2026-6409 | HIGH | 7.1 | 0.4% | Apr 16, 2026 | A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Malici... |
| CVE-2026-3324 | HIGH | 8.2 | 1.3% | Apr 16, 2026 | Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due... |
| CVE-2026-37347 | CRITICAL | 9.1 | 0.3% | Apr 16, 2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_e... |
| CVE-2026-37346 | MEDIUM | 4.7 | 0.2% | Apr 16, 2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_a... |
| CVE-2026-37345 | CRITICAL | 9.8 | 0.3% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_pa... |
| CVE-2026-37344 | HIGH | 7.2 | 0.2% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_lo... |
| CVE-2026-37343 | HIGH | 7.2 | 0.2% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_us... |
| CVE-2026-37342 | HIGH | 7.2 | 0.2% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_park... |
| CVE-2026-37341 | HIGH | 7.2 | 0.2% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_ca... |
| CVE-2026-37340 | CRITICAL | 9.8 | 0.3% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php... |
| CVE-2026-37339 | CRITICAL | 9.8 | 0.3% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php... |
| CVE-2026-37338 | CRITICAL | 9.4 | 0.3% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. |
| CVE-2026-37337 | HIGH | 7.3 | 0.2% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.... |
| CVE-2026-37336 | HIGH | 7.3 | 0.2% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php... |
| CVE-2026-33804 | CRITICAL | 9.1 | 0.3% | Apr 16, 2026 | @fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplica... |
| CVE-2026-30656 | HIGH | 7.5 | 0.3% | Apr 16, 2026 | A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the... |
| CVE-2026-30459 | HIGH | 7.1 | 0.3% | Apr 16, 2026 | An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the... |
| CVE-2026-2840 | MEDIUM | 6.4 | 0.3% | Apr 16, 2026 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2026-6410 | MEDIUM | 5.3 | 0.5% | Apr 16, 2026 | @fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option.... |
| CVE-2026-6270 | CRITICAL | 9.1 | 0.5% | Apr 16, 2026 | @fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instance... |
| CVE-2026-5785 | HIGH | 8.1 | 1.4% | Apr 16, 2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are ... |
| CVE-2026-4160 | MEDIUM | 5.3 | 0.3% | Apr 16, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2026-31987 | HIGH | 7.5 | 0.7% | Apr 16, 2026 | JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to up... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now