2026 CVE Vulnerabilities
51,577 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28221 | HIGH | 8.2 | 0.4% | Apr 29, 2026 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to befo... |
| CVE-2026-27105 | HIGH | 7.1 | 0.1% | Apr 29, 2026 | Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link... |
| CVE-2026-5712 | HIGH | 8.8 | 0.2% | Apr 29, 2026 | This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assi... |
| CVE-2026-6914 | HIGH | 7.5 | 0.3% | Apr 29, 2026 | Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD... |
| CVE-2026-0204 | HIGH | 8 | 0.4% | Apr 29, 2026 | A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access... |
| CVE-2026-7389 | HIGH | 7.3 | 0.3% | Apr 29, 2026 | A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of t... |
| CVE-2026-7386 | HIGH | 7.3 | 0.4% | Apr 29, 2026 | A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp... |
| CVE-2026-6849 | HIGH | 8.8 | 1.0% | Apr 29, 2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG... |
| CVE-2026-42198 | HIGH | 7.5 | 3.3% | Apr 29, 2026 | pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to ... |
| CVE-2026-38991 | HIGH | 8.8 | 0.4% | Apr 29, 2026 | Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function whe... |
| CVE-2026-37555 | HIGH | 7.5 | 0.5% | Apr 29, 2026 | An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) c... |
| CVE-2026-30769 | HIGH | 7.8 | 0.1% | Apr 29, 2026 | An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escal... |
| CVE-2026-7384 | HIGH | 7.3 | 0.4% | Apr 29, 2026 | A vulnerability was detected in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566... |
| CVE-2026-7111 | HIGH | 8.4 | 0.2% | Apr 29, 2026 | Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stac... |
| CVE-2026-5161 | HIGH | 8.8 | 0.3% | Apr 29, 2026 | Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Res... |
| CVE-2026-5141 | HIGH | 8.8 | 0.2% | Apr 29, 2026 | Improper Privilege Management, Improper Access Control, Incorrect privilege assignment vulnerability in TUBITAK BILGEM S... |
| CVE-2026-41952 | HIGH | 7.8 | 0.1% | Apr 29, 2026 | Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP... |
| CVE-2026-41220 | HIGH | 7.8 | 0.1% | Apr 29, 2026 | Local privilege escalation due to improper input validation. The following products are affected: Acronis DeviceLock DLP... |
| CVE-2026-36837 | HIGH | 7.5 | 0.3% | Apr 29, 2026 | TOTOLINK A3002RU V3 <= V3.0.0-B20220304.1804 was discovered to contain a stack-based buffer overflow via the hostname pa... |
| CVE-2026-5140 | HIGH | 8.8 | 0.5% | Apr 29, 2026 | Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM Software Technologies Resea... |
| CVE-2026-42524 | HIGH | 8 | 0.3% | Apr 29, 2026 | Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in ... |
| CVE-2026-42520 | HIGH | 7.5 | 0.4% | Apr 29, 2026 | Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file cre... |
| CVE-2026-42652 | HIGH | 7.1 | 0.1% | Apr 29, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Reg... |
| CVE-2026-42646 | HIGH | 7.6 | 0.2% | Apr 29, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Burge TaxoPr... |
| CVE-2026-42518 | HIGH | 8.7 | 0.2% | Apr 29, 2026 | This vulnerability exists in e-Sushrut due to disclosure of sensitive information and hardcoded AES encryption keys in c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now