2026 CVE Vulnerabilities
53,074 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4344 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked... |
| CVE-2026-2450 | HIGH | 7.4 | 0.3% | Apr 14, 2026 | .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows... |
| CVE-2026-33892 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial... |
| CVE-2026-31923 | HIGH | 7.5 | 0.3% | Apr 14, 2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in o... |
| CVE-2026-27668 | HIGH | 8.8 | 0.3% | Apr 14, 2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). U... |
| CVE-2026-25654 | HIGH | 8.8 | 0.5% | Apr 14, 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate u... |
| CVE-2026-24032 | HIGH | 7.3 | 0.3% | Apr 14, 2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains a... |
| CVE-2026-3017 | HIGH | 7.2 | 0.5% | Apr 14, 2026 | The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to P... |
| CVE-2026-40287 | HIGH | 8.4 | 0.2% | Apr 14, 2026 | PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through a... |
| CVE-2026-6227 | HIGH | 7.2 | 1.3% | Apr 14, 2026 | The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/... |
| CVE-2026-4388 | HIGH | 7.2 | 0.2% | Apr 14, 2026 | The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box... |
| CVE-2026-4352 | HIGH | 7.5 | 0.4% | Apr 14, 2026 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endp... |
| CVE-2026-39421 | HIGH | 7.4 | 0.3% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in ... |
| CVE-2026-39420 | HIGH | 7.4 | 0.5% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mecha... |
| CVE-2026-39418 | HIGH | 7.4 | 0.2% | Apr 14, 2026 | MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypa... |
| CVE-2026-34256 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacke... |
| CVE-2026-40164 | HIGH | 7.5 | 0.4% | Apr 14, 2026 | jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a ... |
| CVE-2026-5086 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuff... |
| CVE-2026-6224 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function... |
| CVE-2026-4786 | HIGH | 7.1 | 0.3% | Apr 13, 2026 | Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain b... |
| CVE-2026-33908 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-33905 | HIGH | 7.1 | 0.2% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-22566 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain U... |
| CVE-2026-22565 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause ... |
| CVE-2026-33901 | HIGH | 7.5 | 0.6% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now