2026 CVE Vulnerabilities
51,445 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6543 | HIGH | 8.8 | 0.5% | Apr 30, 2026 | IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges o... |
| CVE-2026-6542 | HIGH | 8.1 | 0.2% | Apr 30, 2026 | IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build ... |
| CVE-2026-6389 | HIGH | 7.8 | 0.1% | Apr 30, 2026 | IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cl... |
| CVE-2026-40684 | HIGH | 7.5 | 0.4% | Apr 30, 2026 | In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor... |
| CVE-2026-7435 | HIGH | 8.6 | 0.4% | Apr 30, 2026 | SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed ... |
| CVE-2026-4503 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to... |
| CVE-2026-40912 | HIGH | 8.2 | 0.8% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s... |
| CVE-2026-33451 | HIGH | 7.8 | 0.1% | Apr 30, 2026 | CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers w... |
| CVE-2026-33449 | HIGH | 7.5 | 0.2% | Apr 30, 2026 | CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attacker... |
| CVE-2026-7461 | HIGH | 7.5 | 0.5% | Apr 30, 2026 | Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amaz... |
| CVE-2026-40904 | HIGH | 8.1 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-40601 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-40600 | HIGH | 8.1 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-40595 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-3833 | HIGH | 7.4 | 0.6% | Apr 30, 2026 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstra... |
| CVE-2026-36765 | HIGH | 8.8 | 0.3% | Apr 30, 2026 | An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticat... |
| CVE-2026-36762 | HIGH | 8.8 | 0.4% | Apr 30, 2026 | An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers ... |
| CVE-2026-5174 | HIGH | 8.8 | 3.2% | Apr 30, 2026 | Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue ... |
| CVE-2026-36960 | HIGH | 8.8 | 0.2% | Apr 30, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.... |
| CVE-2026-36340 | HIGH | 8.1 | 0.6% | Apr 30, 2026 | An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose e... |
| CVE-2026-36959 | HIGH | 7.5 | 0.4% | Apr 30, 2026 | U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. T... |
| CVE-2026-36958 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concur... |
| CVE-2026-36957 | HIGH | 7.5 | 0.3% | Apr 30, 2026 | Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI h... |
| CVE-2026-36956 | HIGH | 8.8 | 0.2% | Apr 30, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireles... |
| CVE-2026-7246 | HIGH | 7.2 | 0.9% | Apr 30, 2026 | This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Clic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now