2026 CVE Vulnerabilities
66,658 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5322 | HIGH | 7.3 | 0.3% | Apr 2, 2026 | A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69... |
| CVE-2026-4347 | HIGH | 8.1 | 1.3% | Apr 2, 2026 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via ... |
| CVE-2026-1540 | HIGH | 7.2 | 0.6% | Apr 2, 2026 | The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an at... |
| CVE-2026-5321 | MEDIUM | 4.3 | 0.2% | Apr 2, 2026 | A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the compone... |
| CVE-2026-5320 | HIGH | 7.3 | 0.4% | Apr 2, 2026 | A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality o... |
| CVE-2026-5319 | MEDIUM | 4.3 | 0.3% | Apr 2, 2026 | A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown f... |
| CVE-2026-5318 | MEDIUM | 4.3 | 0.6% | Apr 2, 2026 | A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/deco... |
| CVE-2026-5317 | HIGH | 8.8 | 0.4% | Apr 2, 2026 | A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_... |
| CVE-2026-1243 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authe... |
| CVE-2026-5316 | MEDIUM | 6.5 | 0.4% | Apr 2, 2026 | A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file s... |
| CVE-2026-5315 | HIGH | 8.8 | 0.5% | Apr 2, 2026 | A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the l... |
| CVE-2026-21767 | LOW | 3.3 | 0.1% | Apr 2, 2026 | HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive a... |
| CVE-2026-21765 | HIGH | 7.8 | 0.1% | Apr 2, 2026 | HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys l... |
| CVE-2026-5314 | HIGH | 8.8 | 0.7% | Apr 1, 2026 | A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library st... |
| CVE-2026-4759 | — | — | — | Apr 1, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-3882 | — | — | — | Apr 1, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-32929 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 fi... |
| CVE-2026-32928 | HIGH | 8.4 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Op... |
| CVE-2026-32927 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Openi... |
| CVE-2026-32926 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a cra... |
| CVE-2026-32925 | HIGH | 8.4 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Open... |
| CVE-2026-5313 | MEDIUM | 4.3 | 0.3% | Apr 1, 2026 | A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the li... |
| CVE-2026-3987 | HIGH | 7.2 | 0.6% | Apr 1, 2026 | A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authentica... |
| CVE-2026-34572 | HIGH | 8.8 | 0.5% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34571 | CRITICAL | 9 | 0.4% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now