2026 CVE Vulnerabilities
49,078 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7423 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adj... |
| CVE-2026-7397 | MEDIUM | 4.4 | 0.1% | Apr 29, 2026 | A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path ... |
| CVE-2026-41499 | MEDIUM | 6.5 | 0.3% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo... |
| CVE-2026-26206 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to befo... |
| CVE-2026-7396 | MEDIUM | 5.5 | 0.5% | Apr 29, 2026 | A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality ... |
| CVE-2026-7394 | MEDIUM | 4.7 | 0.2% | Apr 29, 2026 | A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2026-26204 | MEDIUM | 5.5 | 0.2% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to befo... |
| CVE-2026-7393 | MEDIUM | 4.7 | 0.3% | Apr 29, 2026 | A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file... |
| CVE-2026-7392 | MEDIUM | 6.3 | 0.2% | Apr 29, 2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function dele... |
| CVE-2026-7391 | MEDIUM | 6.3 | 0.2% | Apr 29, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier... |
| CVE-2026-6915 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen... |
| CVE-2026-0206 | MEDIUM | 4.9 | 0.5% | Apr 29, 2026 | A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewal... |
| CVE-2026-0205 | MEDIUM | 6.8 | 0.4% | Apr 29, 2026 | A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted ser... |
| CVE-2026-7388 | MEDIUM | 4.7 | 0.2% | Apr 29, 2026 | A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/l... |
| CVE-2026-40230 | MEDIUM | 5.4 | 0.2% | Apr 29, 2026 | Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated a... |
| CVE-2026-40229 | MEDIUM | 5.4 | 0.2% | Apr 29, 2026 | Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can per... |
| CVE-2026-38993 | MEDIUM | 6.5 | 0.8% | Apr 29, 2026 | Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows aut... |
| CVE-2026-2810 | MEDIUM | 6.8 | 0.1% | Apr 29, 2026 | Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The succe... |
| CVE-2026-25852 | MEDIUM | 6.7 | 0.1% | Apr 29, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D... |
| CVE-2026-42525 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL... |
| CVE-2026-42522 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers wi... |
| CVE-2026-42521 | MEDIUM | 6.5 | 0.2% | Apr 29, 2026 | Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructor... |
| CVE-2026-42519 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overa... |
| CVE-2026-42648 | MEDIUM | 4.3 | 0.2% | Apr 29, 2026 | Missing Authorization vulnerability in Brainstorm Force Spectra ultimate-addons-for-gutenberg allows Exploiting Incorrec... |
| CVE-2026-42645 | MEDIUM | 4.3 | 0.1% | Apr 29, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Or... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now