2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6219 | MEDIUM | 5.3 | 0.7% | Apr 13, 2026 | A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of ... |
| CVE-2026-6218 | MEDIUM | 5.3 | 0.3% | Apr 13, 2026 | A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode... |
| CVE-2026-6216 | LOW | 3.5 | 0.2% | Apr 13, 2026 | A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/... |
| CVE-2026-33901 | HIGH | 7.5 | 0.6% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-33900 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-33899 | MEDIUM | 5.3 | 0.4% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1... |
| CVE-2026-33740 | MEDIUM | 5.4 | 0.2% | Apr 13, 2026 | EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Em... |
| CVE-2026-33659 | LOW | 3.1 | 0.3% | Apr 13, 2026 | EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/At... |
| CVE-2026-32272 | HIGH | 8.7 | 0.3% | Apr 13, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability e... |
| CVE-2026-32271 | HIGH | 7.7 | 0.5% | Apr 13, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there i... |
| CVE-2026-31280 | MEDIUM | 6.5 | 0.4% | Apr 13, 2026 | An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause... |
| CVE-2026-26460 | MEDIUM | 6.1 | 0.2% | Apr 13, 2026 | A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neu... |
| CVE-2026-6215 | MEDIUM | 6.3 | 0.2% | Apr 13, 2026 | A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file pac... |
| CVE-2026-6202 | MEDIUM | 6.3 | 0.2% | Apr 13, 2026 | A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file po... |
| CVE-2026-6201 | MEDIUM | 5.4 | 0.3% | Apr 13, 2026 | A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the fi... |
| CVE-2026-33657 | MEDIUM | 5.4 | 0.2% | Apr 13, 2026 | EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML inje... |
| CVE-2026-33534 | MEDIUM | 4.3 | 2.0% | Apr 13, 2026 | EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated S... |
| CVE-2026-32605 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2026-32270 | LOW | 1.7 | 0.3% | Apr 13, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the Pay... |
| CVE-2026-31048 | CRITICAL | 9.8 | 0.6% | Apr 13, 2026 | An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a cra... |
| CVE-2026-6200 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the fil... |
| CVE-2026-6199 | HIGH | 8.8 | 0.5% | Apr 13, 2026 | A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting.... |
| CVE-2026-6198 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /... |
| CVE-2026-6197 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/... |
| CVE-2026-40044 | CRITICAL | 9.8 | 0.5% | Apr 13, 2026 | Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now