2026 CVE Vulnerabilities
50,196 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3428 | MEDIUM | 5.4 | 0.1% | Apr 16, 2026 | A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a loca... |
| CVE-2026-1880 | MEDIUM | 5.4 | 0.1% | Apr 16, 2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privi... |
| CVE-2026-40505 | MEDIUM | 4.8 | 0.2% | Apr 16, 2026 | MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI esca... |
| CVE-2026-3299 | MEDIUM | 6.4 | 0.2% | Apr 16, 2026 | The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode ... |
| CVE-2026-4949 | MEDIUM | 4.3 | 0.3% | Apr 15, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2026-40179 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.... |
| CVE-2026-39350 | MEDIUM | 5.4 | 0.2% | Apr 15, 2026 | Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 throug... |
| CVE-2026-1711 | MEDIUM | 4.8 | 0.2% | Apr 15, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interf... |
| CVE-2026-1564 | MEDIUM | 4.8 | 0.2% | Apr 15, 2026 | Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface componen... |
| CVE-2026-40186 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included i... |
| CVE-2026-6385 | MEDIUM | 6.5 | 0.4% | Apr 15, 2026 | A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/... |
| CVE-2026-6364 | MEDIUM | 6.5 | 0.2% | Apr 15, 2026 | Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens... |
| CVE-2026-6362 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out o... |
| CVE-2026-6298 | MEDIUM | 4.3 | 0.3% | Apr 15, 2026 | Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially se... |
| CVE-2026-40919 | MEDIUM | 5.5 | 0.3% | Apr 15, 2026 | A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited... |
| CVE-2026-40918 | MEDIUM | 5.5 | 0.2% | Apr 15, 2026 | A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se... |
| CVE-2026-40916 | MEDIUM | 5.5 | 0.2% | Apr 15, 2026 | A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo... |
| CVE-2026-39857 | MEDIUM | 5.3 | 0.4% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by... |
| CVE-2026-33889 | MEDIUM | 5.4 | 0.2% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site... |
| CVE-2026-33888 | MEDIUM | 5.3 | 0.5% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by... |
| CVE-2026-21726 | MEDIUM | 5.3 | 0.4% | Apr 15, 2026 | The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub... |
| CVE-2026-6383 | MEDIUM | 5.4 | 0.1% | Apr 15, 2026 | A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly... |
| CVE-2026-6245 | MEDIUM | 5.5 | 0.1% | Apr 15, 2026 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA... |
| CVE-2026-40256 | MEDIUM | 5 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre... |
| CVE-2026-39845 | MEDIUM | 4.1 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now