2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6560 | HIGH | 8.8 | 0.5% | Apr 19, 2026 | A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_B... |
| CVE-2026-41254 | HIGH | 7.5 | 0.4% | Apr 18, 2026 | Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed ... |
| CVE-2026-32228 | HIGH | 7.5 | 0.4% | Apr 18, 2026 | UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate t... |
| CVE-2026-30912 | HIGH | 7.5 | 0.4% | Apr 18, 2026 | In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to f... |
| CVE-2026-30898 | HIGH | 8.8 | 0.8% | Apr 18, 2026 | An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause ... |
| CVE-2026-25917 | HIGH | 7.2 | 0.8% | Apr 18, 2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t... |
| CVE-2026-41253 | HIGH | 7.8 | 0.2% | Apr 18, 2026 | In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working ... |
| CVE-2026-6518 | HIGH | 8.8 | 0.9% | Apr 18, 2026 | The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload an... |
| CVE-2026-40491 | HIGH | 7.8 | 0.6% | Apr 18, 2026 | gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack... |
| CVE-2026-40489 | HIGH | 8.6 | 0.2% | Apr 18, 2026 | editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to ... |
| CVE-2026-35582 | HIGH | 8.8 | 0.9% | Apr 18, 2026 | Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable ... |
| CVE-2026-40350 | HIGH | 8.8 | 0.4% | Apr 18, 2026 | Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti... |
| CVE-2026-35465 | HIGH | 7.5 | 0.4% | Apr 18, 2026 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se... |
| CVE-2026-40581 | HIGH | 8.1 | 0.2% | Apr 18, 2026 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (S... |
| CVE-2026-40482 | HIGH | 7.1 | 0.3% | Apr 18, 2026 | ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::ge... |
| CVE-2026-40480 | HIGH | 7.1 | 0.3% | Apr 18, 2026 | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoin... |
| CVE-2026-40349 | HIGH | 8.8 | 0.5% | Apr 18, 2026 | Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti... |
| CVE-2026-40348 | HIGH | 7.7 | 0.4% | Apr 18, 2026 | Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti... |
| CVE-2026-40323 | HIGH | 7.5 | 0.2% | Apr 18, 2026 | SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architectu... |
| CVE-2026-2262 | HIGH | 7.5 | 2.4% | Apr 18, 2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2026-40481 | HIGH | 7.5 | 0.4% | Apr 17, 2026 | monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoi... |
| CVE-2026-40476 | HIGH | 7.5 | 0.5% | Apr 17, 2026 | graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation... |
| CVE-2026-40474 | HIGH | 7.6 | 0.3% | Apr 17, 2026 | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares per... |
| CVE-2026-40352 | HIGH | 8.8 | 0.4% | Apr 17, 2026 | FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to N... |
| CVE-2026-40321 | HIGH | 8 | 7.6% | Apr 17, 2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now