2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40043 | HIGH | 7.1 | 0.3% | Apr 13, 2026 | Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low... |
| CVE-2026-40042 | CRITICAL | 9.8 | 0.4% | Apr 13, 2026 | Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbit... |
| CVE-2026-40041 | MEDIUM | 5.3 | 0.1% | Apr 13, 2026 | Pachno 1.0.6 contains a cross-site request forgery vulnerability that allows attackers to perform arbitrary actions in a... |
| CVE-2026-40040 | HIGH | 8.8 | 0.5% | Apr 13, 2026 | Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file... |
| CVE-2026-40039 | HIGH | 7.1 | 0.3% | Apr 13, 2026 | Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external we... |
| CVE-2026-40038 | HIGH | 7.2 | 0.2% | Apr 13, 2026 | Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and sc... |
| CVE-2026-29955 | HIGH | 8.8 | 2.2% | Apr 13, 2026 | The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. Th... |
| CVE-2026-6196 | HIGH | 8.8 | 0.6% | Apr 13, 2026 | A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeComm... |
| CVE-2026-6195 | CRITICAL | 9.8 | 14.3% | Apr 13, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the funct... |
| CVE-2026-6194 | HIGH | 8.8 | 0.5% | Apr 13, 2026 | A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_41... |
| CVE-2026-6100 | CRITICAL | 9.1 | 0.6% | Apr 13, 2026 | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memo... |
| CVE-2026-32316 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_strin... |
| CVE-2026-28291 | HIGH | 8.1 | 0.7% | Apr 13, 2026 | simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of a... |
| CVE-2026-6193 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of ... |
| CVE-2026-6192 | LOW | 3.3 | 0.1% | Apr 13, 2026 | A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function opj_pi_initialise_encode in ... |
| CVE-2026-6191 | MEDIUM | 6.3 | 0.2% | Apr 13, 2026 | A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of t... |
| CVE-2026-6190 | MEDIUM | 6.3 | 0.2% | Apr 13, 2026 | A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown functio... |
| CVE-2026-6189 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unk... |
| CVE-2026-39940 | MEDIUM | 5.3 | 0.3% | Apr 13, 2026 | ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCR... |
| CVE-2026-36952 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in the file /otas/admin/curriculum/man... |
| CVE-2026-36950 | LOW | 2.7 | 0.2% | Apr 13, 2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerable to SQL injection in /otas/projects_per_department.php. |
| CVE-2026-36948 | HIGH | 7.3 | 0.2% | Apr 13, 2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php. |
| CVE-2026-33555 | MEDIUM | 5.8 | 0.3% | Apr 13, 2026 | An issue was discovered in HAProxy before 3.3.6. The HTTP/3 parser does not check that the received body length matches ... |
| CVE-2026-23891 | HIGH | 8.7 | 0.4% | Apr 13, 2026 | Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code ex... |
| CVE-2026-6231 | HIGH | 7.5 | 0.2% | Apr 13, 2026 | The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could resul... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now