2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22734 | HIGH | 8.6 | 0.4% | Apr 17, 2026 | Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UA... |
| CVE-2026-40318 | HIGH | 8.5 | 0.3% | Apr 16, 2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttr... |
| CVE-2026-40259 | HIGH | 8.1 | 0.4% | Apr 16, 2026 | SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttr... |
| CVE-2026-41113 | HIGH | 8.1 | 0.9% | Apr 16, 2026 | sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remot... |
| CVE-2026-40308 | HIGH | 8.8 | 0.9% | Apr 16, 2026 | My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJA... |
| CVE-2026-40248 | HIGH | 7.5 | 0.4% | Apr 16, 2026 | free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han... |
| CVE-2026-40247 | HIGH | 7.5 | 0.5% | Apr 16, 2026 | free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han... |
| CVE-2026-40246 | HIGH | 7.5 | 0.4% | Apr 16, 2026 | free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the han... |
| CVE-2026-40170 | HIGH | 7.5 | 0.8% | Apr 16, 2026 | ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transpor... |
| CVE-2026-39313 | HIGH | 8.7 | 0.5% | Apr 16, 2026 | mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRe... |
| CVE-2026-40901 | HIGH | 8.8 | 0.6% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocit... |
| CVE-2026-40900 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-33207 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-6442 | HIGH | 8.3 | 0.4% | Apr 16, 2026 | Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands t... |
| CVE-2026-33121 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-33084 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-41082 | HIGH | 7.8 | 0.2% | Apr 16, 2026 | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. |
| CVE-2026-33083 | HIGH | 8.8 | 0.3% | Apr 16, 2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection... |
| CVE-2026-2336 | HIGH | 8.8 | 0.2% | Apr 16, 2026 | A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared ... |
| CVE-2026-6409 | HIGH | 7.1 | 0.4% | Apr 16, 2026 | A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Malici... |
| CVE-2026-3324 | HIGH | 8.2 | 1.3% | Apr 16, 2026 | Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due... |
| CVE-2026-37344 | HIGH | 7.2 | 0.2% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_lo... |
| CVE-2026-37343 | HIGH | 7.2 | 0.2% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_us... |
| CVE-2026-37342 | HIGH | 7.2 | 0.2% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_park... |
| CVE-2026-37341 | HIGH | 7.2 | 0.2% | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_ca... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now