2026 CVE Vulnerabilities
66,632 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28805 | HIGH | 8.8 | 0.5% | Apr 2, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, mu... |
| CVE-2026-26928 | HIGH | 8.7 | 0.2% | Apr 2, 2026 | SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dyna... |
| CVE-2026-26927 | MEDIUM | 5.1 | 0.3% | Apr 2, 2026 | Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched... |
| CVE-2026-5331 | MEDIUM | 4.7 | 0.4% | Apr 2, 2026 | A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the compon... |
| CVE-2026-5330 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some ... |
| CVE-2026-5328 | MEDIUM | 6.3 | 0.2% | Apr 2, 2026 | A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted e... |
| CVE-2026-4636 | HIGH | 8.1 | 0.3% | Apr 2, 2026 | A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) po... |
| CVE-2026-4634 | HIGH | 7.5 | 0.7% | Apr 2, 2026 | A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted ... |
| CVE-2026-4325 | MEDIUM | 5.3 | 0.3% | Apr 2, 2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso... |
| CVE-2026-4282 | HIGH | 7.4 | 0.4% | Apr 2, 2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso... |
| CVE-2026-3872 | HIGH | 7.3 | 0.4% | Apr 2, 2026 | A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass... |
| CVE-2026-34890 | MEDIUM | 6.5 | 0.1% | Apr 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MST... |
| CVE-2026-5327 | MEDIUM | 6.3 | 1.1% | Apr 2, 2026 | A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function h... |
| CVE-2026-23417 | MEDIUM | 5.5 | 0.1% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores ... |
| CVE-2026-23416 | MEDIUM | 5.5 | 0.2% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update VMA end correctly on merge Previo... |
| CVE-2026-23415 | HIGH | 7.8 | 0.1% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and ... |
| CVE-2026-23414 | MEDIUM | 5.5 | 0.2% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() ... |
| CVE-2026-23413 | HIGH | 7.8 | 0.1% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback... |
| CVE-2026-23412 | HIGH | 7.8 | 0.1% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu... |
| CVE-2026-5326 | MEDIUM | 5.5 | 0.4% | Apr 2, 2026 | A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-32145 | HIGH | 7.5 | 0.6% | Apr 2, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via mul... |
| CVE-2026-5246 | HIGH | 8.1 | 0.6% | Apr 2, 2026 | A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of ... |
| CVE-2026-5245 | HIGH | 8.1 | 0.7% | Apr 2, 2026 | A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongo... |
| CVE-2026-33617 | MEDIUM | 5.3 | 0.3% | Apr 2, 2026 | An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a... |
| CVE-2026-33616 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now