2026 CVE Vulnerabilities
65,056 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40502 | HIGH | 8.8 | 1.7% | Apr 16, 2026 | OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with cha... |
| CVE-2026-5363 | HIGH | 8.8 | 0.1% | Apr 16, 2026 | Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery ... |
| CVE-2026-4880 | CRITICAL | 9.8 | 0.5% | Apr 16, 2026 | The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPres... |
| CVE-2026-40947 | LOW | 2.9 | 0.1% | Apr 16, 2026 | Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search... |
| CVE-2026-40245 | HIGH | 7.5 | 0.5% | Apr 16, 2026 | Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and belo... |
| CVE-2026-40193 | HIGH | 8.2 | 0.4% | Apr 16, 2026 | maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the au... |
| CVE-2026-4949 | MEDIUM | 4.3 | 0.3% | Apr 15, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2026-40316 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m... |
| CVE-2026-40192 | HIGH | 7.5 | 0.7% | Apr 15, 2026 | Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read... |
| CVE-2026-40179 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.... |
| CVE-2026-39350 | MEDIUM | 5.4 | 0.2% | Apr 15, 2026 | Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 throug... |
| CVE-2026-6388 | CRITICAL | 9.1 | 0.4% | Apr 15, 2026 | A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an... |
| CVE-2026-40500 | — | — | 0.4% | Apr 15, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" fe... |
| CVE-2026-1711 | MEDIUM | 4.8 | 0.2% | Apr 15, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interf... |
| CVE-2026-1564 | MEDIUM | 4.8 | 0.2% | Apr 15, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface componen... |
| CVE-2026-6398 | — | — | — | Apr 15, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-40261 | HIGH | 8.8 | 1.7% | Apr 15, 2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection ... |
| CVE-2026-40186 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included i... |
| CVE-2026-40176 | HIGH | 7.8 | 1.1% | Apr 15, 2026 | Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection ... |
| CVE-2026-40173 | CRITICAL | 9.4 | 0.5% | Apr 15, 2026 | Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential d... |
| CVE-2026-22676 | HIGH | 8.5 | 0.1% | Apr 15, 2026 | Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gai... |
| CVE-2026-6385 | MEDIUM | 6.5 | 0.4% | Apr 15, 2026 | A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/... |
| CVE-2026-6384 | HIGH | 7.8 | 0.3% | Apr 15, 2026 | A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` funct... |
| CVE-2026-6364 | MEDIUM | 6.5 | 0.2% | Apr 15, 2026 | Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens... |
| CVE-2026-6363 | HIGH | 8.8 | 0.3% | Apr 15, 2026 | Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now