2026 CVE Vulnerabilities
50,301 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6364 | MEDIUM | 6.5 | 0.2% | Apr 15, 2026 | Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens... |
| CVE-2026-6362 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out o... |
| CVE-2026-6298 | MEDIUM | 4.3 | 0.3% | Apr 15, 2026 | Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially se... |
| CVE-2026-40919 | MEDIUM | 5.5 | 0.3% | Apr 15, 2026 | A flaw was found in GIMP. This vulnerability, a buffer overflow in the `file-seattle-filmworks` plugin, can be exploited... |
| CVE-2026-40918 | MEDIUM | 5.5 | 0.2% | Apr 15, 2026 | A flaw was found in GIMP. Processing a specially crafted PVR image file with large dimensions can lead to a denial of se... |
| CVE-2026-40916 | MEDIUM | 5.5 | 0.2% | Apr 15, 2026 | A flaw was found in GIMP. A stack buffer overflow vulnerability in the TIM image loader's 4BPP decoding path allows a lo... |
| CVE-2026-39857 | MEDIUM | 5.3 | 0.4% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by... |
| CVE-2026-33889 | MEDIUM | 5.4 | 0.2% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a stored cross-site... |
| CVE-2026-33888 | MEDIUM | 5.3 | 0.5% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain an authorization by... |
| CVE-2026-21726 | MEDIUM | 5.3 | 0.4% | Apr 15, 2026 | The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub... |
| CVE-2026-6383 | MEDIUM | 5.4 | 0.1% | Apr 15, 2026 | A flaw was found in KubeVirt's Role-Based Access Control (RBAC) evaluation logic. The authorization mechanism improperly... |
| CVE-2026-6245 | MEDIUM | 5.5 | 0.1% | Apr 15, 2026 | A flaw was found in the System Security Services Daemon (SSSD). The pam_passkey_child_read_data() function within the PA... |
| CVE-2026-40256 | MEDIUM | 5 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre... |
| CVE-2026-39845 | MEDIUM | 4.1 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr... |
| CVE-2026-34244 | MEDIUM | 5 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by... |
| CVE-2026-33440 | MEDIUM | 5 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t... |
| CVE-2026-33220 | MEDIUM | 6.8 | 0.3% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo... |
| CVE-2026-5758 | MEDIUM | 6.5 | 0.5% | Apr 15, 2026 | JavaScript is vulnerable to prototype pollution in Mafintosh's protocol-buffers-schema Version 3.6.0, where an attacker ... |
| CVE-2026-33214 | MEDIUM | 4.3 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo... |
| CVE-2026-6370 | MEDIUM | 5.9 | 0.1% | Apr 15, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj... |
| CVE-2026-20170 | MEDIUM | 6.1 | 0.2% | Apr 15, 2026 | A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, ... |
| CVE-2026-20161 | MEDIUM | 5.5 | 0.1% | Apr 15, 2026 | A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low ... |
| CVE-2026-20152 | MEDIUM | 5.3 | 0.3% | Apr 15, 2026 | A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all... |
| CVE-2026-20148 | MEDIUM | 4.9 | 9.2% | Apr 15, 2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a... |
| CVE-2026-20136 | MEDIUM | 6 | 0.5% | Apr 15, 2026 | A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now