2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4667 | HIGH | 7.3 | 0.1% | Apr 15, 2026 | HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate th... |
| CVE-2026-30364 | HIGH | 7.5 | 0.3% | Apr 15, 2026 | CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function. |
| CVE-2026-4145 | HIGH | 7.8 | 0.2% | Apr 15, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow... |
| CVE-2026-4135 | MEDIUM | 6.6 | 0.1% | Apr 15, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins... |
| CVE-2026-4134 | HIGH | 7.3 | 0.1% | Apr 15, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins... |
| CVE-2026-25219 | MEDIUM | 6.5 | 0.6% | Apr 15, 2026 | The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi... |
| CVE-2026-1636 | MEDIUM | 6.7 | 0.1% | Apr 15, 2026 | A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo... |
| CVE-2026-0827 | HIGH | 7.1 | 0.2% | Apr 15, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareS... |
| CVE-2026-3590 | MEDIUM | 6.5 | 0.1% | Apr 15, 2026 | Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin... |
| CVE-2026-1852 | MEDIUM | 6.1 | 0.1% | Apr 15, 2026 | The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2026-40786 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured A... |
| CVE-2026-40784 | HIGH | 8.1 | 0.2% | Apr 15, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows ... |
| CVE-2026-40778 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly ... |
| CVE-2026-40764 | HIGH | 8.1 | 0.1% | Apr 15, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Re... |
| CVE-2026-40763 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows Exploiting Incorrec... |
| CVE-2026-40745 | HIGH | 7.6 | 0.2% | Apr 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element P... |
| CVE-2026-40744 | HIGH | 8.5 | 0.2% | Apr 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Bea... |
| CVE-2026-40742 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Exploiting Incorrectly Co... |
| CVE-2026-40740 | MEDIUM | 5.4 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in Themeum Tutor LMS tutor allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-40737 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in VillaTheme COMPE compe-woo-compare-products allows Exp... |
| CVE-2026-40734 | MEDIUM | 6.5 | 0.1% | Apr 15, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zahlan Categories ... |
| CVE-2026-40730 | MEDIUM | 5.3 | 0.2% | Apr 15, 2026 | Missing Authorization vulnerability in ThemeGrill ThemeGrill Demo Importer themegrill-demo-importer allows Exploiting In... |
| CVE-2026-40729 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Missing Authorization vulnerability in bPlugins 3D viewer – Embed 3D Models 3d-viewer allows Exploiting Incorrectly Conf... |
| CVE-2026-40728 | MEDIUM | 4.3 | 0.1% | Apr 15, 2026 | Missing Authorization vulnerability in BlockArt Magazine Blocks magazine-blocks allows Exploiting Incorrectly Configured... |
| CVE-2026-33805 | HIGH | 8.6 | 0.4% | Apr 15, 2026 | @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection head... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now