2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5189 | CRITICAL | 9.8 | 0.5% | Apr 15, 2026 | CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unau... |
| CVE-2026-4857 | HIGH | 8.4 | 0.3% | Apr 15, 2026 | IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prio... |
| CVE-2026-40256 | MEDIUM | 5 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre... |
| CVE-2026-39845 | MEDIUM | 4.1 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr... |
| CVE-2026-34632 | HIGH | 8.6 | 0.3% | Apr 15, 2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in ... |
| CVE-2026-34393 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limi... |
| CVE-2026-34244 | MEDIUM | 5 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by... |
| CVE-2026-34242 | HIGH | 7.7 | 0.4% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded f... |
| CVE-2026-33667 | HIGH | 7.4 | 0.3% | Apr 15, 2026 | OpenProject is an open-source project management application. In versions prior to 17.3.0, 2FA OTP verification in the c... |
| CVE-2026-33440 | MEDIUM | 5 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t... |
| CVE-2026-33435 | HIGH | 8 | 0.7% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial ... |
| CVE-2026-33220 | MEDIUM | 6.8 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo... |
| CVE-2026-6290 | CRITICAL | 9.1 | 0.2% | Apr 15, 2026 | Velociraptor versions prior to 0.76.3 contain a vulnerability in the query() plugin which allows access to all orgs with... |
| CVE-2026-5758 | MEDIUM | 6.5 | 0.5% | Apr 15, 2026 | JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker ... |
| CVE-2026-33214 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo... |
| CVE-2026-33212 | LOW | 3.1 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending... |
| CVE-2026-32631 | HIGH | 7.4 | 0.3% | Apr 15, 2026 | Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent atta... |
| CVE-2026-30993 | CRITICAL | 9.8 | 0.5% | Apr 15, 2026 | Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() functio... |
| CVE-2026-6372 | HIGH | 7.5 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in Plisio Accept Cryptocurrencies with Plisio allows Exploiting Incorrectly Configur... |
| CVE-2026-6370 | MEDIUM | 5.9 | 0.1% | Apr 15, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj... |
| CVE-2026-30996 | HIGH | 7.5 | 0.7% | Apr 15, 2026 | An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a direc... |
| CVE-2026-30995 | HIGH | 8.6 | 0.2% | Apr 15, 2026 | Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_v... |
| CVE-2026-30994 | HIGH | 7.5 | 0.3% | Apr 15, 2026 | Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access... |
| CVE-2026-20186 | CRITICAL | 9.9 | 5.9% | Apr 15, 2026 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra... |
| CVE-2026-20184 | CRITICAL | 9.8 | 0.5% | Apr 15, 2026 | A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now