2026 CVE Vulnerabilities
53,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34256 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | Due to a missing authorization check in SAP ERP and SAP S/4HANA (Private Cloud and On-Premise), an authenticated attacke... |
| CVE-2026-40164 | HIGH | 7.5 | 0.4% | Apr 14, 2026 | jq is a command-line JSON processor. Before commit 0c7d133c3c7e37c00b6d46b658a02244fdd3c784, jq used MurmurHash3 with a ... |
| CVE-2026-5086 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks. For example, if Crypt::SecretBuff... |
| CVE-2026-6224 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function... |
| CVE-2026-4786 | HIGH | 7.1 | 0.3% | Apr 13, 2026 | Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain b... |
| CVE-2026-33908 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-33905 | HIGH | 7.1 | 0.2% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-22566 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An Improper Access Control vulnerability could allow a malicious actor with access to the UniFi Play network to obtain U... |
| CVE-2026-22565 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An Improper Input Validation vulnerability could allow a malicious actor with access to the UniFi Play network to cause ... |
| CVE-2026-33901 | HIGH | 7.5 | 0.6% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-33900 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.... |
| CVE-2026-32272 | HIGH | 8.7 | 0.3% | Apr 13, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability e... |
| CVE-2026-32271 | HIGH | 7.7 | 0.5% | Apr 13, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there i... |
| CVE-2026-32605 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a... |
| CVE-2026-6200 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the fil... |
| CVE-2026-6199 | HIGH | 8.8 | 0.5% | Apr 13, 2026 | A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting.... |
| CVE-2026-6198 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /... |
| CVE-2026-6197 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/... |
| CVE-2026-40043 | HIGH | 7.1 | 0.3% | Apr 13, 2026 | Pachno 1.0.6 contains an authentication bypass vulnerability in the runSwitchUser() action that allows authenticated low... |
| CVE-2026-40040 | HIGH | 8.8 | 0.5% | Apr 13, 2026 | Pachno 1.0.6 contains an unrestricted file upload vulnerability that allows authenticated users to upload arbitrary file... |
| CVE-2026-40039 | HIGH | 7.1 | 0.3% | Apr 13, 2026 | Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external we... |
| CVE-2026-40038 | HIGH | 7.2 | 0.2% | Apr 13, 2026 | Pachno 1.0.6 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary HTML and sc... |
| CVE-2026-29955 | HIGH | 8.8 | 2.2% | Apr 13, 2026 | The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. Th... |
| CVE-2026-6196 | HIGH | 8.8 | 0.6% | Apr 13, 2026 | A vulnerability was detected in Tenda F456 1.0.0.5. This affects the function fromexeCommand of the file /goform/exeComm... |
| CVE-2026-6194 | HIGH | 8.8 | 0.5% | Apr 13, 2026 | A weakness has been identified in Totolink A3002MU B20211125.1046. Affected by this vulnerability is the function sub_41... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now