2026 CVE Vulnerabilities
66,632 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33615 | CRITICAL | 9.1 | 0.4% | Apr 2, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint du... |
| CVE-2026-33614 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint du... |
| CVE-2026-33613 | HIGH | 8.8 | 0.5% | Apr 2, 2026 | Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulne... |
| CVE-2026-29144 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security... |
| CVE-2026-29143 | CRITICAL | 9.1 | 0.3% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted... |
| CVE-2026-29142 | MEDIUM | 5.3 | 0.1% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email. |
| CVE-2026-29141 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags suc... |
| CVE-2026-29140 | MEDIUM | 5.3 | 0.1% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be u... |
| CVE-2026-29139 | CRITICAL | 9.8 | 0.3% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to re... |
| CVE-2026-29138 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim ano... |
| CVE-2026-29137 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a lo... |
| CVE-2026-29136 | MEDIUM | 6.1 | 0.1% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new... |
| CVE-2026-29135 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject san... |
| CVE-2026-29134 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass... |
| CVE-2026-29133 | CRITICAL | 9.1 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match th... |
| CVE-2026-29132 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass ... |
| CVE-2026-29131 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the ... |
| CVE-2026-0634 | HIGH | 7.8 | 0.5% | Apr 2, 2026 | Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as ... |
| CVE-2026-5244 | CRITICAL | 9.8 | 0.7% | Apr 2, 2026 | A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mo... |
| CVE-2026-5032 | HIGH | 7.5 | 1.0% | Apr 2, 2026 | The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.... |
| CVE-2026-0688 | MEDIUM | 6.4 | 0.2% | Apr 2, 2026 | The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5... |
| CVE-2026-0686 | HIGH | 7.2 | 0.3% | Apr 2, 2026 | The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5... |
| CVE-2026-5325 | LOW | 3.5 | 0.2% | Apr 2, 2026 | A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects ... |
| CVE-2026-5323 | MEDIUM | 5.3 | 0.1% | Apr 2, 2026 | A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the ... |
| CVE-2026-5322 | HIGH | 7.3 | 0.3% | Apr 2, 2026 | A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now