2026 CVE Vulnerabilities
49,039 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33450 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with ... |
| CVE-2026-28532 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing... |
| CVE-2026-7429 | MEDIUM | 4.6 | 0.2% | Apr 30, 2026 | SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attacker... |
| CVE-2026-40603 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-35514 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-32148 | MEDIUM | 5.9 | 0.2% | Apr 30, 2026 | Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency... |
| CVE-2026-36766 | MEDIUM | 5.4 | 0.1% | Apr 30, 2026 | Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer ... |
| CVE-2026-36763 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 al... |
| CVE-2026-36761 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers... |
| CVE-2026-36764 | MEDIUM | 5 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows aut... |
| CVE-2026-36757 | MEDIUM | 4.3 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authentica... |
| CVE-2026-38940 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code ... |
| CVE-2026-38939 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code... |
| CVE-2026-36759 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticat... |
| CVE-2026-36758 | MEDIUM | 4.3 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated at... |
| CVE-2026-36756 | MEDIUM | 5.4 | 0.1% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated a... |
| CVE-2026-7500 | MEDIUM | 5.4 | 0.2% | Apr 30, 2026 | When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled... |
| CVE-2026-7163 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Mul... |
| CVE-2026-7382 | MEDIUM | 6.5 | 0.3% | Apr 30, 2026 | Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized ... |
| CVE-2026-5080 | MEDIUM | 5.9 | 0.4% | Apr 30, 2026 | Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generate... |
| CVE-2026-1493 | MEDIUM | 5.4 | 0.2% | Apr 30, 2026 | LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the para... |
| CVE-2026-31692 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check f... |
| CVE-2026-6498 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in ve... |
| CVE-2026-42800 | MEDIUM | 5.3 | 0.2% | Apr 30, 2026 | NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Mani... |
| CVE-2026-41016 | MEDIUM | 5.9 | 0.3% | Apr 30, 2026 | Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certif... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now