2026 CVE Vulnerabilities
50,042 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40479 | MEDIUM | 5.4 | 0.2% | Apr 17, 2026 | Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in Ki... |
| CVE-2026-2434 | MEDIUM | 6.4 | 0.2% | Apr 17, 2026 | The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute... |
| CVE-2026-40353 | MEDIUM | 5.4 | 0.2% | Apr 17, 2026 | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in Abs... |
| CVE-2026-40306 | MEDIUM | 6.5 | 0.2% | Apr 17, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new in... |
| CVE-2026-40305 | MEDIUM | 4.3 | 0.2% | Apr 17, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i... |
| CVE-2026-40304 | MEDIUM | 5.3 | 0.3% | Apr 17, 2026 | zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (c... |
| CVE-2026-40302 | MEDIUM | 6.1 | 0.2% | Apr 17, 2026 | zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template en... |
| CVE-2026-40301 | MEDIUM | 4.7 | 0.3% | Apr 17, 2026 | DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style... |
| CVE-2026-40299 | MEDIUM | 6.9 | 0.3% | Apr 17, 2026 | next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9.... |
| CVE-2026-40293 | MEDIUM | 6.5 | 0.3% | Apr 17, 2026 | OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is co... |
| CVE-2026-40284 | MEDIUM | 6.8 | 0.2% | Apr 17, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul... |
| CVE-2026-40282 | MEDIUM | 6.4 | 0.3% | Apr 17, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul... |
| CVE-2026-40155 | MEDIUM | 5.4 | 0.2% | Apr 17, 2026 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 thro... |
| CVE-2026-33436 | MEDIUM | 6.1 | 0.2% | Apr 17, 2026 | Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to ... |
| CVE-2026-33145 | MEDIUM | 6.3 | 0.4% | Apr 17, 2026 | xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary comma... |
| CVE-2026-35061 | MEDIUM | 5.3 | 0.3% | Apr 17, 2026 | Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication,... |
| CVE-2026-33569 | MEDIUM | 6.5 | 0.2% | Apr 17, 2026 | Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and ses... |
| CVE-2026-33093 | MEDIUM | 5.3 | 0.2% | Apr 17, 2026 | Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing c... |
| CVE-2026-32648 | MEDIUM | 5.3 | 0.2% | Apr 17, 2026 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/R... |
| CVE-2026-32624 | MEDIUM | 6.5 | 0.4% | Apr 17, 2026 | xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its log... |
| CVE-2026-31927 | MEDIUM | 4.9 | 0.4% | Apr 17, 2026 | Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files... |
| CVE-2026-6437 | MEDIUM | 6.9 | 0.4% | Apr 17, 2026 | Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-drive... |
| CVE-2026-28214 | MEDIUM | 6.5 | 1.1% | Apr 17, 2026 | Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the Clum... |
| CVE-2026-40319 | MEDIUM | 5.5 | 0.1% | Apr 17, 2026 | Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes ... |
| CVE-2026-40516 | MEDIUM | 6.3 | 0.2% | Apr 17, 2026 | OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now