2026 CVE Vulnerabilities
52,215 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39110 | HIGH | 8.2 | 0.3% | Apr 20, 2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 in the con... |
| CVE-2026-6662 | HIGH | 7.3 | 0.2% | Apr 20, 2026 | A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src... |
| CVE-2026-41445 | HIGH | 8.8 | 0.3% | Apr 20, 2026 | KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fft... |
| CVE-2026-40488 | HIGH | 8.8 | 0.7% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-30266 | HIGH | 7.8 | 0.1% | Apr 20, 2026 | Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbit... |
| CVE-2026-26943 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-26942 | HIGH | 7.2 | 0.9% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i... |
| CVE-2026-25524 | HIGH | 8.1 | 0.5% | Apr 20, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-24506 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-24505 | HIGH | 7.2 | 0.4% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability. A high privi... |
| CVE-2026-24504 | HIGH | 7.2 | 0.4% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-22761 | HIGH | 7.2 | 1.2% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att... |
| CVE-2026-6066 | HIGH | 7.1 | 0.1% | Apr 20, 2026 | ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automa... |
| CVE-2026-41245 | HIGH | 7.5 | 0.3% | Apr 20, 2026 | Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFold... |
| CVE-2026-40896 | HIGH | 7.1 | 0.2% | Apr 20, 2026 | OpenProject is open-source, web-based project management software. Prior to version 17.3.0, a user with `manage_agendas`... |
| CVE-2026-34428 | HIGH | 8.3 | 0.3% | Apr 20, 2026 | Vvveb prior to 1.0.8.1 contains a server-side request forgery vulnerability in the oEmbedProxy action of the editor/edit... |
| CVE-2026-34427 | HIGH | 8.8 | 0.6% | Apr 20, 2026 | Vvveb prior to 1.0.8.1 contains a privilege escalation vulnerability in the admin user profile save endpoint that allows... |
| CVE-2026-26944 | HIGH | 8.8 | 0.5% | Apr 20, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r... |
| CVE-2026-25058 | HIGH | 7.5 | 0.4% | Apr 20, 2026 | Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve... |
| CVE-2026-23774 | HIGH | 7.2 | 1.5% | Apr 20, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,... |
| CVE-2026-4048 | HIGH | 7.2 | 2.1% | Apr 20, 2026 | OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker... |
| CVE-2026-3519 | HIGH | 7.2 | 2.1% | Apr 20, 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke... |
| CVE-2026-3518 | HIGH | 7.2 | 2.5% | Apr 20, 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke... |
| CVE-2026-3517 | HIGH | 7.2 | 18.2% | Apr 20, 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke... |
| CVE-2026-6635 | HIGH | 7.3 | 0.5% | Apr 20, 2026 | A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now