2026 CVE Vulnerabilities
53,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32316 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | jq is a command-line JSON processor. An integer overflow vulnerability exists through version 1.8.1 within the jvp_strin... |
| CVE-2026-28291 | HIGH | 8.1 | 0.7% | Apr 13, 2026 | simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of a... |
| CVE-2026-6193 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of ... |
| CVE-2026-6189 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. The affected element is an unk... |
| CVE-2026-36948 | HIGH | 7.3 | 0.2% | Apr 13, 2026 | Sourcecodester Online Thesis Archiving System v1.0 is vulnerale to SQL injection in the file /otas/view_archive.php. |
| CVE-2026-23891 | HIGH | 8.7 | 0.4% | Apr 13, 2026 | Decidim is a participatory democracy framework. In versions below 0.30.5 and 0.31.0.rc1 through 0.31.0, a stored code ex... |
| CVE-2026-6231 | HIGH | 7.5 | 0.2% | Apr 13, 2026 | The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could resul... |
| CVE-2026-6188 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the ... |
| CVE-2026-6187 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. This issue affects some unknown ... |
| CVE-2026-6186 | HIGH | 8.8 | 0.6% | Apr 13, 2026 | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This vulnerability affects the functi... |
| CVE-2026-34188 | HIGH | 7.2 | 1.1% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Event Re... |
| CVE-2026-34186 | HIGH | 8.8 | 0.2% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via custom fields.... |
| CVE-2026-30813 | HIGH | 8.8 | 0.3% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command vulnerability allows SQL Injection via module search.... |
| CVE-2026-30809 | HIGH | 8.8 | 0.9% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via WebServe... |
| CVE-2026-30806 | HIGH | 8.8 | 0.9% | Apr 13, 2026 | Improper Neutralization of Special Elements used in an OS Command vulnerability allows OS Command Injection via Network ... |
| CVE-2026-30804 | HIGH | 7.2 | 0.4% | Apr 13, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability allows Remote Code Execution via file upload. This issue a... |
| CVE-2026-6183 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is som... |
| CVE-2026-6182 | HIGH | 7.3 | 0.3% | Apr 13, 2026 | A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is ... |
| CVE-2026-33858 | HIGH | 8.8 | 0.6% | Apr 13, 2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t... |
| CVE-2026-31281 | HIGH | 8 | 0.3% | Apr 13, 2026 | Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message a... |
| CVE-2026-30999 | HIGH | 7.5 | 0.5% | Apr 13, 2026 | A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Servi... |
| CVE-2026-30998 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows att... |
| CVE-2026-30997 | HIGH | 7.5 | 0.3% | Apr 13, 2026 | An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cau... |
| CVE-2026-1462 | HIGH | 8.8 | 0.4% | Apr 13, 2026 | A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow S... |
| CVE-2026-31426 | HIGH | 7 | 0.1% | Apr 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: ACPI: EC: clean up handlers on probe failure in acp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now