2026 CVE Vulnerabilities
66,711 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4829 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an ... |
| CVE-2026-4828 | HIGH | 8.2 | 0.3% | Apr 1, 2026 | Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att... |
| CVE-2026-35099 | HIGH | 7.4 | 0.1% | Apr 1, 2026 | Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. Th... |
| CVE-2026-34510 | MEDIUM | 6.9 | 0.3% | Apr 1, 2026 | OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file... |
| CVE-2026-31027 | CRITICAL | 9.8 | 0.6% | Apr 1, 2026 | TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste... |
| CVE-2026-30573 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is loc... |
| CVE-2026-30526 | MEDIUM | 6.1 | 0.3% | Apr 1, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerabil... |
| CVE-2026-30523 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input vali... |
| CVE-2026-30292 | HIGH | 8.4 | 0.1% | Apr 1, 2026 | An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite ... |
| CVE-2026-30291 | HIGH | 8.4 | 0.1% | Apr 1, 2026 | An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwr... |
| CVE-2026-29598 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora... |
| CVE-2026-5271 | HIGH | 7.8 | 0.2% | Apr 1, 2026 | pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current... |
| CVE-2026-3877 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution a... |
| CVE-2026-35094 | MEDIUM | 5.5 | 0.1% | Apr 1, 2026 | A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl... |
| CVE-2026-35093 | HIGH | 8.8 | 0.2% | Apr 1, 2026 | A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or ... |
| CVE-2026-35092 | HIGH | 7.5 | 1.0% | Apr 1, 2026 | A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a re... |
| CVE-2026-35091 | HIGH | 8.2 | 0.9% | Apr 1, 2026 | A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Co... |
| CVE-2026-34999 | MEDIUM | 6.9 | 0.4% | Apr 1, 2026 | OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that al... |
| CVE-2026-34430 | CRITICAL | 9.6 | 0.4% | Apr 1, 2026 | ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that al... |
| CVE-2026-30522 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validati... |
| CVE-2026-30289 | HIGH | 8.4 | 0.2% | Apr 1, 2026 | An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrit... |
| CVE-2026-30287 | HIGH | 8.4 | 0.2% | Apr 1, 2026 | An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to ... |
| CVE-2026-0522 | HIGH | 8.8 | 0.6% | Apr 1, 2026 | A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated att... |
| CVE-2026-29014 | CRITICAL | 9.8 | 39.7% | Apr 1, 2026 | MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at... |
| CVE-2026-22768 | HIGH | 7.3 | 0.1% | Apr 1, 2026 | Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now