2026 CVE Vulnerabilities
50,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39845 | MEDIUM | 4.1 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr... |
| CVE-2026-34244 | MEDIUM | 5 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by... |
| CVE-2026-33440 | MEDIUM | 5 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t... |
| CVE-2026-33220 | MEDIUM | 6.8 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo... |
| CVE-2026-5758 | MEDIUM | 6.5 | 0.5% | Apr 15, 2026 | JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker ... |
| CVE-2026-33214 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo... |
| CVE-2026-6370 | MEDIUM | 5.9 | 0.1% | Apr 15, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj... |
| CVE-2026-20170 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, ... |
| CVE-2026-20161 | MEDIUM | 5.5 | 0.1% | Apr 15, 2026 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low ... |
| CVE-2026-20152 | MEDIUM | 5.3 | 0.3% | Apr 15, 2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all... |
| CVE-2026-20148 | MEDIUM | 4.9 | 9.2% | Apr 15, 2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a... |
| CVE-2026-20136 | MEDIUM | 6 | 0.5% | Apr 15, 2026 | A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI... |
| CVE-2026-20132 | MEDIUM | 4.8 | 0.2% | Apr 15, 2026 | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au... |
| CVE-2026-20081 | MEDIUM | 6.5 | 0.4% | Apr 15, 2026 | Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr... |
| CVE-2026-20078 | MEDIUM | 6.5 | 0.4% | Apr 15, 2026 | Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr... |
| CVE-2026-20061 | MEDIUM | 6.5 | 0.2% | Apr 15, 2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att... |
| CVE-2026-20060 | MEDIUM | 4.7 | 0.2% | Apr 15, 2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a... |
| CVE-2026-20059 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a... |
| CVE-2026-20203 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-20202 | MEDIUM | 6.6 | 0.2% | Apr 15, 2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-4135 | MEDIUM | 6.6 | 0.1% | Apr 15, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins... |
| CVE-2026-25219 | MEDIUM | 6.5 | 0.6% | Apr 15, 2026 | The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. Thi... |
| CVE-2026-1636 | MEDIUM | 6.7 | 0.1% | Apr 15, 2026 | A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allo... |
| CVE-2026-3590 | MEDIUM | 6.5 | 0.1% | Apr 15, 2026 | Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic sin... |
| CVE-2026-1852 | MEDIUM | 6.1 | 0.1% | Apr 15, 2026 | The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now