2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39410 | MEDIUM | 4.8 | 0.3% | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a discrepancy be... |
| CVE-2026-39409 | MEDIUM | 5.3 | 0.3% | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, ipRestriction() ... |
| CVE-2026-39408 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal... |
| CVE-2026-39407 | MEDIUM | 5.3 | 0.5% | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path handling ... |
| CVE-2026-39406 | MEDIUM | 5.3 | 0.4% | Apr 8, 2026 | @hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in ser... |
| CVE-2026-39394 | CRITICAL | 9.8 | 0.5% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-39393 | HIGH | 8.1 | 0.4% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-39392 | MEDIUM | 4.8 | 0.2% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-39391 | MEDIUM | 4.8 | 0.2% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-39390 | MEDIUM | 4.8 | 0.2% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-39389 | HIGH | 7.2 | 0.5% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-5795 | HIGH | 7.4 | 0.5% | Apr 8, 2026 | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. ... |
| CVE-2026-35023 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | Wimi Teamwork On-Premises versions prior to 8.2.0 contain an insecure direct object reference vulnerability in the previ... |
| CVE-2026-31411 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: atm: fix crash due to unvalidated vcc pointer ... |
| CVE-2026-2509 | MEDIUM | 6.4 | 0.3% | Apr 8, 2026 | The Page Builder: Pagelayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button widget's Cu... |
| CVE-2026-5600 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact... |
| CVE-2026-5302 | HIGH | 8.1 | 0.3% | Apr 8, 2026 | CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and se... |
| CVE-2026-5301 | MEDIUM | 6.1 | 0.3% | Apr 8, 2026 | Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the serv... |
| CVE-2026-5300 | CRITICAL | 9.1 | 0.2% | Apr 8, 2026 | Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modif... |
| CVE-2026-4402 | — | — | — | Apr 8, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-28261 | MEDIUM | 5.5 | 0.1% | Apr 8, 2026 | Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0... |
| CVE-2026-27102 | HIGH | 7.8 | 0.1% | Apr 8, 2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect p... |
| CVE-2026-24511 | MEDIUM | 4.4 | 0.2% | Apr 8, 2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.0, contains a generation o... |
| CVE-2026-5208 | HIGH | 7.2 | 1.0% | Apr 8, 2026 | Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary c... |
| CVE-2026-3396 | HIGH | 7.5 | 1.5% | Apr 8, 2026 | WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' parameter... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now