2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-37337 | HIGH | 7.3 | 0.2% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.... |
| CVE-2026-37336 | HIGH | 7.3 | 0.2% | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php... |
| CVE-2026-30656 | HIGH | 7.5 | 0.3% | Apr 16, 2026 | A NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the... |
| CVE-2026-30459 | HIGH | 7.1 | 0.3% | Apr 16, 2026 | An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the... |
| CVE-2026-5785 | HIGH | 8.1 | 1.4% | Apr 16, 2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are ... |
| CVE-2026-31987 | HIGH | 7.5 | 0.7% | Apr 16, 2026 | JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to up... |
| CVE-2026-3489 | HIGH | 7.5 | 0.4% | Apr 16, 2026 | The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection vi... |
| CVE-2026-23772 | HIGH | 7.3 | 0.1% | Apr 16, 2026 | Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management... |
| CVE-2026-41035 | HIGH | 7.8 | 0.4% | Apr 16, 2026 | In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiv... |
| CVE-2026-3876 | HIGH | 7.2 | 0.3% | Apr 16, 2026 | The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-short... |
| CVE-2026-3861 | HIGH | 7.1 | 0.3% | Apr 16, 2026 | LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web ... |
| CVE-2026-1620 | HIGH | 8.8 | 0.8% | Apr 16, 2026 | The Livemesh Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
| CVE-2026-5050 | HIGH | 7.5 | 0.2% | Apr 16, 2026 | The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptog... |
| CVE-2026-3614 | HIGH | 8.8 | 0.4% | Apr 16, 2026 | The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and includi... |
| CVE-2026-3599 | HIGH | 7.5 | 0.5% | Apr 16, 2026 | The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within... |
| CVE-2026-22618 | HIGH | 7.1 | 0.2% | Apr 16, 2026 | A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was... |
| CVE-2026-22617 | HIGH | 7.4 | 0.2% | Apr 16, 2026 | Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacke... |
| CVE-2026-22616 | HIGH | 7.5 | 0.3% | Apr 16, 2026 | Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login... |
| CVE-2026-22615 | HIGH | 7.2 | 0.3% | Apr 16, 2026 | Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attack... |
| CVE-2026-6351 | HIGH | 8.7 | 0.6% | Apr 16, 2026 | MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers ... |
| CVE-2026-41015 | HIGH | 7.4 | 1.2% | Apr 16, 2026 | radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE... |
| CVE-2026-40960 | HIGH | 8.1 | 0.2% | Apr 16, 2026 | Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as s... |
| CVE-2026-40503 | HIGH | 7.1 | 0.4% | Apr 16, 2026 | OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat a... |
| CVE-2026-40502 | HIGH | 8.8 | 1.7% | Apr 16, 2026 | OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with cha... |
| CVE-2026-5363 | HIGH | 8.8 | 0.1% | Apr 16, 2026 | Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now