2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33705 | MEDIUM | 5.3 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ ... |
| CVE-2026-33704 | HIGH | 8.8 | 0.4% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arb... |
| CVE-2026-33703 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerabili... |
| CVE-2026-33702 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Ob... |
| CVE-2026-33698 | CRITICAL | 9.8 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code fr... |
| CVE-2026-33618 | HIGH | 8.8 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray... |
| CVE-2026-27460 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a c... |
| CVE-2026-5483 | CRITICAL | 9.9 | 0.5% | Apr 10, 2026 | A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Ha... |
| CVE-2026-40163 | HIGH | 8.2 | 0.3% | Apr 10, 2026 | Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, t... |
| CVE-2026-40162 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugs... |
| CVE-2026-33141 | MEDIUM | 6.5 | 0.1% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerabili... |
| CVE-2026-32932 | MEDIUM | 6.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the sess... |
| CVE-2026-32931 | HIGH | 8.8 | 0.5% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability ... |
| CVE-2026-32930 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)... |
| CVE-2026-32894 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)... |
| CVE-2026-32893 | MEDIUM | 5.4 | 0.1% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability i... |
| CVE-2026-32892 | HIGH | 8.8 | 1.5% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injecti... |
| CVE-2026-31941 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request... |
| CVE-2026-31940 | HIGH | 8.8 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled ... |
| CVE-2026-31939 | HIGH | 8.3 | 0.4% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php... |
| CVE-2026-1502 | MEDIUM | 5.7 | 0.6% | Apr 10, 2026 | CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. |
| CVE-2026-40200 | HIGH | 8.1 | 0.1% | Apr 10, 2026 | An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very ... |
| CVE-2026-40160 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied UR... |
| CVE-2026-40159 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows s... |
| CVE-2026-40158 | HIGH | 7.8 | 0.2% | Apr 10, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using ty... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now