2026 CVE Vulnerabilities
52,233 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30615 | HIGH | 8 | 0.3% | Apr 15, 2026 | A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim... |
| CVE-2026-30461 | HIGH | 8.3 | 0.6% | Apr 15, 2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ... |
| CVE-2026-20205 | HIGH | 7.2 | 0.3% | Apr 15, 2026 | In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or p... |
| CVE-2026-20204 | HIGH | 7.1 | 3.3% | Apr 15, 2026 | In Splunk Enterprise versions below 10.2.1, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-4682 | HIGH | 8.7 | 0.3% | Apr 15, 2026 | Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specia... |
| CVE-2026-4667 | HIGH | 7.3 | 0.1% | Apr 15, 2026 | HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate th... |
| CVE-2026-30364 | HIGH | 7.5 | 0.3% | Apr 15, 2026 | CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function. |
| CVE-2026-4145 | HIGH | 7.8 | 0.2% | Apr 15, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow... |
| CVE-2026-4134 | HIGH | 7.3 | 0.1% | Apr 15, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during ins... |
| CVE-2026-0827 | HIGH | 7.1 | 0.2% | Apr 15, 2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareS... |
| CVE-2026-40784 | HIGH | 8.1 | 0.2% | Apr 15, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows ... |
| CVE-2026-40764 | HIGH | 8.1 | 0.1% | Apr 15, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Re... |
| CVE-2026-40745 | HIGH | 7.6 | 0.2% | Apr 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bdthemes Element P... |
| CVE-2026-40744 | HIGH | 8.5 | 0.2% | Apr 15, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beaver Builder Bea... |
| CVE-2026-33805 | HIGH | 8.6 | 0.4% | Apr 15, 2026 | @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the client's Connection head... |
| CVE-2026-30778 | HIGH | 7.5 | 0.5% | Apr 15, 2026 | The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL. Th... |
| CVE-2026-28741 | HIGH | 8.1 | 0.1% | Apr 15, 2026 | Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF toke... |
| CVE-2026-5598 | HIGH | 8.9 | 0.7% | Apr 15, 2026 | Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulne... |
| CVE-2026-5588 | HIGH | 7.5 | 0.6% | Apr 15, 2026 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all... |
| CVE-2026-3505 | HIGH | 7.5 | 0.8% | Apr 15, 2026 | Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the B... |
| CVE-2026-5694 | HIGH | 7.2 | 0.3% | Apr 15, 2026 | The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'l... |
| CVE-2026-5617 | HIGH | 8.8 | 0.4% | Apr 15, 2026 | The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3... |
| CVE-2026-3643 | HIGH | 7.2 | 0.4% | Apr 15, 2026 | The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to,... |
| CVE-2026-5088 | HIGH | 7.5 | 0.6% | Apr 15, 2026 | Apache::API::Password versions through 0.5.2 for Perl can generate insecure random values for salts. The _make_salt and... |
| CVE-2026-40719 | HIGH | 7.5 | 0.4% | Apr 15, 2026 | Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver addr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now