2026 CVE Vulnerabilities
50,000 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33431 | MEDIUM | 6.5 | 0.4% | Apr 20, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS... |
| CVE-2026-29647 | MEDIUM | 6.5 | 0.2% | Apr 20, 2026 | In OpenXiangShan NEMU, insufficient Smstateen permission enforcement allows lower-privileged code to access IMSIC state ... |
| CVE-2026-6550 | MEDIUM | 5.7 | 0.1% | Apr 20, 2026 | Cryptographic algorithm downgrade in the caching layer of Amazon AWS Encryption SDK for Python before version 3.3.1 and ... |
| CVE-2026-6060 | MEDIUM | 4.5 | 0.2% | Apr 20, 2026 | A vulnerability in the SQL Box in the admin interface of OTRS leads to an uncontrolled resource consumption leading to a... |
| CVE-2026-41389 | MEDIUM | 6.3 | 0.3% | Apr 20, 2026 | OpenClaw versions 2026.4.7 before 2026.4.15 fail to enforce local-root containment on tool-result media paths, allowing ... |
| CVE-2026-39112 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | Cross Site Scripting vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in ... |
| CVE-2026-26399 | MEDIUM | 5.3 | 0.2% | Apr 20, 2026 | A stack-use-after-return issue exists in the Arduino_Core_STM32 library prior to version 1.7.0. The pwm_start() function... |
| CVE-2026-23758 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows ... |
| CVE-2026-23757 | MEDIUM | 5.4 | 0.1% | Apr 20, 2026 | GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title p... |
| CVE-2026-23756 | MEDIUM | 5.4 | 0.1% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the s... |
| CVE-2026-23753 | MEDIUM | 4.8 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality... |
| CVE-2026-23752 | MEDIUM | 4.8 | 0.2% | Apr 20, 2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editi... |
| CVE-2026-40098 | MEDIUM | 5.4 | 0.2% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-35154 | MEDIUM | 6.7 | 0.1% | Apr 20, 2026 | Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers... |
| CVE-2026-28684 | MEDIUM | 6.6 | 0.2% | Apr 20, 2026 | python-dotenv reads key-value pairs from a .env file and can set them as environment variables. Prior to version 1.2.2, ... |
| CVE-2026-26951 | MEDIUM | 6.7 | 0.1% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-25525 | MEDIUM | 4.9 | 0.5% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-6652 | MEDIUM | 4.7 | 0.2% | Apr 20, 2026 | A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/mod... |
| CVE-2026-6650 | MEDIUM | 4.7 | 0.2% | Apr 20, 2026 | A vulnerability was identified in Z-BlogPHP 1.7.5. This affects the function App::UnPack of the file /zb_users/plugin/Ap... |
| CVE-2026-3219 | MEDIUM | 4.6 | 0.1% | Apr 20, 2026 | pip handles concatenated tar and ZIP files as ZIP files regardless of filename or whether a file is both a tar and ZIP f... |
| CVE-2026-34429 | MEDIUM | 5.4 | 0.3% | Apr 20, 2026 | Vvveb prior to 1.0.8.1 contains a stored cross-site scripting vulnerability that allows authenticated users with media u... |
| CVE-2026-25883 | MEDIUM | 5.8 | 0.2% | Apr 20, 2026 | Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve... |
| CVE-2026-24468 | MEDIUM | 5.3 | 0.3% | Apr 20, 2026 | OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa... |
| CVE-2026-6649 | MEDIUM | 6.3 | 0.2% | Apr 20, 2026 | A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/... |
| CVE-2026-6369 | MEDIUM | 5.5 | 0.1% | Apr 20, 2026 | An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now