2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27672 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | The Material Master application does not enforce authorization checks for authenticated users when executing reports, re... |
| CVE-2026-24318 | MEDIUM | 4.2 | 0.2% | Apr 14, 2026 | Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthent... |
| CVE-2026-0512 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management (SICF Handler in SRM Catal... |
| CVE-2026-6203 | MEDIUM | 6.1 | 0.7% | Apr 13, 2026 | The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5... |
| CVE-2026-5086 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuff... |
| CVE-2026-39979 | MEDIUM | 6.5 | 0.6% | Apr 13, 2026 | jq is a command-line JSON processor. In commits before 2f09060afab23fe9390cce7cb860b10416e1bf5f, the jv_parse_sized() AP... |
| CVE-2026-39956 | MEDIUM | 6.1 | 0.2% | Apr 13, 2026 | jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its ar... |
| CVE-2026-6224 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function... |
| CVE-2026-6220 | MEDIUM | 4.7 | 0.2% | Apr 13, 2026 | A vulnerability was identified in HummerRisk up to 1.5.0. This vulnerability affects the function ServerService.addServe... |
| CVE-2026-4786 | HIGH | 7.1 | 0.3% | Apr 13, 2026 | Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain b... |
| CVE-2026-40312 | MEDIUM | 5.5 | 0.2% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1... |
| CVE-2026-40311 | MEDIUM | 5.5 | 0.2% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below 7.1.2-19 a... |
| CVE-2026-40310 | MEDIUM | 5.5 | 0.2% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versions below both 7.1.2... |
| CVE-2026-40183 | MEDIUM | 5.5 | 0.2% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1... |
| CVE-2026-40169 | MEDIUM | 5.5 | 0.2% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1... |
| CVE-2026-34238 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-33947 | MEDIUM | 5.5 | 0.2% | Apr 13, 2026 | jq is a command-line JSON processor. In versions 1.8.1 and below, functions jv_setpath(), jv_getpath(), and delpaths_sor... |
| CVE-2026-33908 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-33905 | HIGH | 7.1 | 0.2% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-33902 | MEDIUM | 5.5 | 0.1% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-22566 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain U... |
| CVE-2026-22565 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause ... |
| CVE-2026-22564 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to enable S... |
| CVE-2026-22563 | CRITICAL | 9.8 | 1.1% | Apr 13, 2026 | A series of Improper Input Validation vulnerabilities could allow a Command Injection by a malicious actor with access t... |
| CVE-2026-22562 | CRITICAL | 9.8 | 0.8% | Apr 13, 2026 | A malicious actor with access to the UniFi Play network could exploit a Path Traversal vulnerability found in the device... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now