2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35249 | LOW | 3.2 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-34312 | LOW | 2.4 | 0.2% | Apr 21, 2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea... |
| CVE-2026-34268 | LOW | 2.9 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-22018 | LOW | 3.7 | 0.3% | Apr 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-22014 | LOW | 3.8 | 0.2% | Apr 21, 2026 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events)... |
| CVE-2026-22008 | LOW | 3.7 | 0.2% | Apr 21, 2026 | Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0... |
| CVE-2026-22007 | LOW | 2.9 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE... |
| CVE-2026-22001 | LOW | 2.7 | 0.3% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t... |
| CVE-2026-40878 | LOW | 2.1 | 0.8% | Apr 21, 2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow ... |
| CVE-2026-6745 | LOW | 3.5 | 0.2% | Apr 21, 2026 | A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of th... |
| CVE-2026-6743 | LOW | 3.5 | 0.2% | Apr 21, 2026 | A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. ... |
| CVE-2026-40279 | LOW | 3.7 | 0.2% | Apr 21, 2026 | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in... |
| CVE-2026-29179 | LOW | 3.3 | 0.1% | Apr 21, 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission c... |
| CVE-2026-27937 | LOW | 3.1 | 0.1% | Apr 21, 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Script... |
| CVE-2026-31369 | LOW | 3.2 | 0.1% | Apr 21, 2026 | PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availab... |
| CVE-2026-40264 | LOW | 2.7 | 0.3% | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation... |
| CVE-2026-39388 | LOW | 3.1 | 0.1% | Apr 21, 2026 | OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authen... |
| CVE-2026-6651 | LOW | 2.4 | 0.2% | Apr 20, 2026 | A security flaw has been discovered in erponline.xyz ERP Online up to 4.0.0. This vulnerability affects unknown code of ... |
| CVE-2026-6648 | LOW | 3.5 | 0.2% | Apr 20, 2026 | A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component I... |
| CVE-2026-6633 | LOW | 3.5 | 0.3% | Apr 20, 2026 | A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file pl... |
| CVE-2026-5958 | LOW | 2.1 | 0.1% | Apr 20, 2026 | When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separ... |
| CVE-2026-6624 | LOW | 2.4 | 0.2% | Apr 20, 2026 | A weakness has been identified in BichitroGan ISP Billing Software 2025.3.20. Affected is an unknown function of the fil... |
| CVE-2026-6622 | LOW | 2.4 | 0.2% | Apr 20, 2026 | A vulnerability was identified in BichitroGan ISP Billing Software 2025.3.20. This affects an unknown function of the fi... |
| CVE-2026-6619 | LOW | 3.5 | 0.2% | Apr 20, 2026 | A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/ap... |
| CVE-2026-6611 | LOW | 3.1 | 0.2% | Apr 20, 2026 | A vulnerability was found in liangliangyy DjangoBlog up to 2.1.0.0. This affects an unknown function of the file djangob... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now