2026 CVE Vulnerabilities
50,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32629 | MEDIUM | 6.1 | 0.3% | Apr 2, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest F... |
| CVE-2026-5332 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of t... |
| CVE-2026-30867 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exist... |
| CVE-2026-2737 | MEDIUM | 6.1 | 0.2% | Apr 2, 2026 | A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a ma... |
| CVE-2026-26927 | MEDIUM | 5.1 | 0.3% | Apr 2, 2026 | Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched... |
| CVE-2026-5331 | MEDIUM | 4.7 | 0.4% | Apr 2, 2026 | A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the compon... |
| CVE-2026-5330 | MEDIUM | 6.5 | 0.3% | Apr 2, 2026 | A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some ... |
| CVE-2026-5328 | MEDIUM | 6.3 | 0.2% | Apr 2, 2026 | A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted e... |
| CVE-2026-4325 | MEDIUM | 5.3 | 0.3% | Apr 2, 2026 | A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso... |
| CVE-2026-34890 | MEDIUM | 6.5 | 0.1% | Apr 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MST... |
| CVE-2026-5327 | MEDIUM | 6.3 | 1.1% | Apr 2, 2026 | A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function h... |
| CVE-2026-23417 | MEDIUM | 5.5 | 0.1% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores ... |
| CVE-2026-23416 | MEDIUM | 5.5 | 0.2% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update VMA end correctly on merge Previo... |
| CVE-2026-23414 | MEDIUM | 5.5 | 0.2% | Apr 2, 2026 | In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() ... |
| CVE-2026-5326 | MEDIUM | 5.5 | 0.4% | Apr 2, 2026 | A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the fi... |
| CVE-2026-33617 | MEDIUM | 5.3 | 0.3% | Apr 2, 2026 | An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a... |
| CVE-2026-29144 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security... |
| CVE-2026-29142 | MEDIUM | 5.3 | 0.1% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email. |
| CVE-2026-29141 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags suc... |
| CVE-2026-29140 | MEDIUM | 5.3 | 0.1% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be u... |
| CVE-2026-29137 | MEDIUM | 5.3 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a lo... |
| CVE-2026-29136 | MEDIUM | 6.1 | 0.1% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new... |
| CVE-2026-0688 | MEDIUM | 6.4 | 0.2% | Apr 2, 2026 | The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5... |
| CVE-2026-5323 | MEDIUM | 5.3 | 0.1% | Apr 2, 2026 | A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the ... |
| CVE-2026-5321 | MEDIUM | 4.3 | 0.2% | Apr 2, 2026 | A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the compone... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now