2026 CVE Vulnerabilities
66,372 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35543 | MEDIUM | 5.3 | 0.4% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed... |
| CVE-2026-35542 | MEDIUM | 5.3 | 0.4% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed... |
| CVE-2026-35541 | MEDIUM | 4.2 | 0.2% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plu... |
| CVE-2026-35540 | MEDIUM | 6.5 | 0.3% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization... |
| CVE-2026-35539 | MEDIUM | 6.1 | 0.3% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachmen... |
| CVE-2026-35538 | LOW | 3.1 | 0.3% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could l... |
| CVE-2026-5452 | LOW | 3.3 | 0.1% | Apr 3, 2026 | A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the f... |
| CVE-2026-35537 | HIGH | 7.5 | 0.5% | Apr 3, 2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache sess... |
| CVE-2026-35536 | MEDIUM | 5.3 | 0.2% | Apr 3, 2026 | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .Req... |
| CVE-2026-35535 | HIGH | 7.8 | 0.2% | Apr 3, 2026 | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop befor... |
| CVE-2026-28815 | HIGH | 7.5 | 0.5% | Apr 3, 2026 | A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulati... |
| CVE-2026-35508 | MEDIUM | 6.1 | 0.2% | Apr 3, 2026 | Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters, |
| CVE-2026-35507 | MEDIUM | 6.5 | 0.1% | Apr 3, 2026 | Shynet before 0.14.0 allows Host header injection in the password reset flow. |
| CVE-2026-33107 | CRITICAL | 9.8 | 0.7% | Apr 3, 2026 | Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a netw... |
| CVE-2026-33105 | CRITICAL | 9.8 | 0.7% | Apr 3, 2026 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over ... |
| CVE-2026-32213 | CRITICAL | 9.8 | 0.9% | Apr 3, 2026 | Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-32211 | HIGH | 7.5 | 0.8% | Apr 3, 2026 | Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information... |
| CVE-2026-32173 | HIGH | 7.5 | 0.9% | Apr 3, 2026 | Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-26135 | HIGH | 8.8 | 0.6% | Apr 3, 2026 | Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to ele... |
| CVE-2026-35467 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other error... |
| CVE-2026-35466 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from C... |
| CVE-2026-30252 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l Zen... |
| CVE-2026-30251 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenSh... |
| CVE-2026-5420 | LOW | 2.5 | 0.1% | Apr 2, 2026 | A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown f... |
| CVE-2026-35383 | MEDIUM | 6.9 | 0.3% | Apr 2, 2026 | Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated att... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now