2026 CVE Vulnerabilities
52,193 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34403 | HIGH | 8.1 | 0.2% | Apr 20, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui u... |
| CVE-2026-33626 | HIGH | 7.5 | 45.3% | Apr 20, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Ser... |
| CVE-2026-33031 | HIGH | 8.1 | 0.3% | Apr 20, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an adminis... |
| CVE-2026-29648 | HIGH | 8.8 | 0.3% | Apr 20, 2026 | In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0.ENVCFG does not correctly restrict access to henvcf... |
| CVE-2026-29642 | HIGH | 7.8 | 0.1% | Apr 20, 2026 | A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted ... |
| CVE-2026-6249 | HIGH | 8.8 | 0.6% | Apr 20, 2026 | Vvveb CMS 1.0.8.2 contains a remote code execution vulnerability in its media upload handler that allows authenticated a... |
| CVE-2026-5478 | HIGH | 8.1 | 1.0% | Apr 20, 2026 | The Everest Forms plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in all versions up to, and incl... |
| CVE-2026-32135 | HIGH | 7.5 | 0.5% | Apr 20, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Versions prior to 0.24.11 have a remotely triggera... |
| CVE-2026-29645 | HIGH | 7.5 | 0.5% | Apr 20, 2026 | NEMU (OpenXiangShan/NEMU) before v2025.12.r2 contains an improper instruction-validation flaw in its RISC-V Vector (RVV)... |
| CVE-2026-6248 | HIGH | 8.1 | 0.6% | Apr 20, 2026 | The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.5. Th... |
| CVE-2026-39111 | HIGH | 7.5 | 0.3% | Apr 20, 2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the ema... |
| CVE-2026-39110 | HIGH | 8.2 | 0.3% | Apr 20, 2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con... |
| CVE-2026-6662 | HIGH | 7.3 | 0.2% | Apr 20, 2026 | A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src... |
| CVE-2026-41445 | HIGH | 8.8 | 0.3% | Apr 20, 2026 | KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft... |
| CVE-2026-40488 | HIGH | 8.8 | 0.7% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-30266 | HIGH | 7.8 | 0.1% | Apr 20, 2026 | Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbit... |
| CVE-2026-26943 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-26942 | HIGH | 7.2 | 0.9% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i... |
| CVE-2026-25524 | HIGH | 8.1 | 0.5% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-24506 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-24505 | HIGH | 7.2 | 0.4% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privi... |
| CVE-2026-24504 | HIGH | 7.2 | 0.4% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-22761 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att... |
| CVE-2026-6066 | HIGH | 7.1 | 0.1% | Apr 20, 2026 | ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automa... |
| CVE-2026-41245 | HIGH | 7.5 | 0.3% | Apr 20, 2026 | Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFold... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now