2026 CVE Vulnerabilities
50,981 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20097 | MEDIUM | 6.5 | 0.5% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20096 | MEDIUM | 6.5 | 0.7% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20095 | MEDIUM | 6.5 | 0.9% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20090 | MEDIUM | 4.8 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20089 | MEDIUM | 4.8 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20088 | MEDIUM | 4.8 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20087 | MEDIUM | 4.8 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20085 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to co... |
| CVE-2026-20042 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encrypt... |
| CVE-2026-20041 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attac... |
| CVE-2026-5175 | MEDIUM | 5 | 0.3% | Apr 1, 2026 | Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti... |
| CVE-2026-4989 | MEDIUM | 4.3 | 0.2% | Apr 1, 2026 | Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate... |
| CVE-2026-4927 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi... |
| CVE-2026-4925 | MEDIUM | 5 | 0.2% | Apr 1, 2026 | Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra... |
| CVE-2026-4829 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an ... |
| CVE-2026-34510 | MEDIUM | 6.9 | 0.3% | Apr 1, 2026 | OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file... |
| CVE-2026-30526 | MEDIUM | 6.1 | 0.3% | Apr 1, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerabil... |
| CVE-2026-30523 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input vali... |
| CVE-2026-29598 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora... |
| CVE-2026-3877 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution a... |
| CVE-2026-35094 | MEDIUM | 5.5 | 0.1% | Apr 1, 2026 | A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl... |
| CVE-2026-34999 | MEDIUM | 6.9 | 0.4% | Apr 1, 2026 | OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that al... |
| CVE-2026-30522 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validati... |
| CVE-2026-25601 | MEDIUM | 6.7 | 0.2% | Apr 1, 2026 | A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contai... |
| CVE-2026-21632 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Lack of output escaping for article titles leads to XSS vectors in various locations. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now