2026 CVE Vulnerabilities
66,714 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0522 | HIGH | 8.8 | 0.6% | Apr 1, 2026 | A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated att... |
| CVE-2026-29014 | CRITICAL | 9.8 | 39.7% | Apr 1, 2026 | MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at... |
| CVE-2026-22768 | HIGH | 7.3 | 0.1% | Apr 1, 2026 | Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low... |
| CVE-2026-22767 | HIGH | 7.3 | 0.2% | Apr 1, 2026 | Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged att... |
| CVE-2026-25601 | MEDIUM | 6.7 | 0.2% | Apr 1, 2026 | A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contai... |
| CVE-2026-24096 | HIGH | 8.8 | 0.2% | Apr 1, 2026 | Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5... |
| CVE-2026-0932 | HIGH | 7.3 | 0.2% | Apr 1, 2026 | Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in... |
| CVE-2026-23899 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | An improper access check allows unauthorized access to webservice endpoints. |
| CVE-2026-23898 | HIGH | 7.2 | 0.5% | Apr 1, 2026 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. |
| CVE-2026-21632 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Lack of output escaping for article titles leads to XSS vectors in various locations. |
| CVE-2026-21631 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. |
| CVE-2026-21630 | HIGH | 8.8 | 0.3% | Apr 1, 2026 | Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint. |
| CVE-2026-21629 | HIGH | 7.3 | 0.2% | Apr 1, 2026 | The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was pote... |
| CVE-2026-1879 | MEDIUM | 6.3 | 0.3% | Apr 1, 2026 | A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the fil... |
| CVE-2026-5261 | HIGH | 7.3 | 0.4% | Apr 1, 2026 | A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uplo... |
| CVE-2026-4370 | CRITICAL | 10 | 0.4% | Apr 1, 2026 | A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the inter... |
| CVE-2026-34889 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force U... |
| CVE-2026-23411 | HIGH | 7.8 | 0.1% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs acce... |
| CVE-2026-23410 | HIGH | 7.8 | 0.1% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is... |
| CVE-2026-23409 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix differential encoding verification D... |
| CVE-2026-23408 | HIGH | 7.8 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_... |
| CVE-2026-23407 | HIGH | 7.8 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table... |
| CVE-2026-23406 | HIGH | 7.8 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro... |
| CVE-2026-23405 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix: limit the number of levels of policy... |
| CVE-2026-23404 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with it... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now