2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40077 | LOW | 3.1 | 0.2% | Apr 9, 2026 | Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied sys... |
| CVE-2026-5836 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A vulnerability has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functional... |
| CVE-2026-5835 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A flaw has been found in code-projects Online Shoe Store 1.0. Affected by this vulnerability is an unknown functionality... |
| CVE-2026-5834 | LOW | 2.4 | 0.2% | Apr 9, 2026 | A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/... |
| CVE-2026-4916 | LOW | 2.7 | 0.3% | Apr 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.8.9, 18.9 before 18.9.5, and 1... |
| CVE-2026-5810 | LOW | 3.5 | 0.2% | Apr 8, 2026 | A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /del... |
| CVE-2026-5806 | LOW | 3.5 | 0.2% | Apr 8, 2026 | A security vulnerability has been detected in code-projects Easy Blog Site 1.0. This affects an unknown function of the ... |
| CVE-2026-39510 | LOW | 2.7 | 0.2% | Apr 8, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-ti... |
| CVE-2026-34781 | LOW | 3.3 | 0.1% | Apr 7, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5,... |
| CVE-2026-39349 | LOW | 2.7 | 0.1% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source encrypts cer... |
| CVE-2026-39347 | LOW | 2.7 | 0.2% | Apr 7, 2026 | OrangeHRM is a comprehensive human resource management (HRM) system. From 5.0 to 5.8, OrangeHRM Open Source accepts chan... |
| CVE-2026-39321 | LOW | 3.7 | 0.2% | Apr 7, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a... |
| CVE-2026-5382 | LOW | 3 | 0.2% | Apr 7, 2026 | An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resol... |
| CVE-2026-5381 | LOW | 2.2 | 0.2% | Apr 7, 2026 | An issue that could expose task information outside of the authorized organization scope has been resolved. This is an i... |
| CVE-2026-5379 | LOW | 3 | 0.1% | Apr 7, 2026 | An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope h... |
| CVE-2026-5375 | LOW | 2.7 | 0.2% | Apr 7, 2026 | An issue that could allow a user with access to a credential to view sensitive fields through an API response has been r... |
| CVE-2026-4292 | LOW | 2.7 | 0.3% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `Mod... |
| CVE-2026-28810 | LOW | 3.7 | 0.3% | Apr 7, 2026 | Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows D... |
| CVE-2026-35448 | LOW | 3.7 | 0.3% | Apr 6, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoin... |
| CVE-2026-5682 | LOW | 3.7 | 0.2% | Apr 6, 2026 | A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of t... |
| CVE-2026-5668 | LOW | 2.4 | 0.2% | Apr 6, 2026 | A flaw has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affect... |
| CVE-2026-5647 | LOW | 2.4 | 0.2% | Apr 6, 2026 | A vulnerability was detected in code-projects Online Shoe Store 1.0. This affects an unknown part of the file /admin/adm... |
| CVE-2026-5644 | LOW | 2.4 | 0.2% | Apr 6, 2026 | A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3... |
| CVE-2026-5643 | LOW | 2.4 | 0.2% | Apr 6, 2026 | A vulnerability was identified in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th... |
| CVE-2026-5622 | LOW | 3.7 | 0.3% | Apr 6, 2026 | A vulnerability was determined in hcengineering Huly Platform 0.7.382. Affected by this issue is some unknown functional... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now