2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30814 | HIGH | 8 | 0.4% | Apr 8, 2026 | A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attac... |
| CVE-2026-2942 | CRITICAL | 9.8 | 0.6% | Apr 8, 2026 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2026-27806 | HIGH | 7.8 | 0.1% | Apr 8, 2026 | Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotati... |
| CVE-2026-20709 | MEDIUM | 6.6 | 0.1% | Apr 8, 2026 | Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(... |
| CVE-2026-0814 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2026-0811 | MEDIUM | 5.4 | 0.1% | Apr 8, 2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2026-33756 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query b... |
| CVE-2026-33466 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and po... |
| CVE-2026-33459 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)... |
| CVE-2026-33458 | HIGH | 7.7 | 0.2% | Apr 8, 2026 | Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user w... |
| CVE-2026-32591 | MEDIUM | 5.5 | 0.3% | Apr 8, 2026 | A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an u... |
| CVE-2026-32590 | HIGH | 8.8 | 0.4% | Apr 8, 2026 | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores interm... |
| CVE-2026-32589 | HIGH | 7.4 | 0.2% | Apr 8, 2026 | A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any reposit... |
| CVE-2026-4837 | HIGH | 7.2 | 0.4% | Apr 8, 2026 | An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically all... |
| CVE-2026-4498 | HIGH | 7.7 | 0.3% | Apr 8, 2026 | Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index dat... |
| CVE-2026-33461 | MEDIUM | 6.5 | 0.3% | Apr 8, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). A user w... |
| CVE-2026-33460 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to cross-space information disclosure via Privilege Abuse (CAPEC-12... |
| CVE-2026-31017 | CRITICAL | 9.1 | 0.2% | Apr 8, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the Print Format functionality of ERPNext v16.0.1 and Frapp... |
| CVE-2026-30080 | HIGH | 7.5 | 0.3% | Apr 8, 2026 | OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported int... |
| CVE-2026-30075 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentic... |
| CVE-2026-2377 | MEDIUM | 6.5 | 0.4% | Apr 8, 2026 | A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products all... |
| CVE-2026-33753 | HIGH | 7.5 | 0.2% | Apr 8, 2026 | rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an ... |
| CVE-2026-33229 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8... |
| CVE-2026-31040 | CRITICAL | 9.8 | 0.6% | Apr 8, 2026 | A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-fil... |
| CVE-2026-39865 | MEDIUM | 5.9 | 0.7% | Apr 8, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now