2026 CVE Vulnerabilities
53,121 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4157 | HIGH | 7.5 | 0.9% | Apr 11, 2026 | ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows ne... |
| CVE-2026-4156 | HIGH | 7.5 | 0.4% | Apr 11, 2026 | ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability a... |
| CVE-2026-4155 | HIGH | 7.5 | 0.6% | Apr 11, 2026 | ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulne... |
| CVE-2026-4154 | HIGH | 7.8 | 0.6% | Apr 11, 2026 | GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t... |
| CVE-2026-4153 | HIGH | 7.8 | 0.7% | Apr 11, 2026 | GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-4152 | HIGH | 7.8 | 0.7% | Apr 11, 2026 | GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-4151 | HIGH | 7.8 | 0.7% | Apr 11, 2026 | GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t... |
| CVE-2026-4150 | HIGH | 7.8 | 0.8% | Apr 11, 2026 | GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers t... |
| CVE-2026-3690 | HIGH | 7.4 | 0.7% | Apr 11, 2026 | OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication... |
| CVE-2026-40198 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_... |
| CVE-2026-40252 | HIGH | 8.1 | 0.3% | Apr 10, 2026 | FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any... |
| CVE-2026-40188 | HIGH | 7.7 | 0.3% | Apr 10, 2026 | goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the... |
| CVE-2026-40180 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.... |
| CVE-2026-40177 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a... |
| CVE-2026-40168 | HIGH | 8.2 | 0.4% | Apr 10, 2026 | Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Al... |
| CVE-2026-32252 | HIGH | 7.7 | 0.3% | Apr 10, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-33710 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time... |
| CVE-2026-33706 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify the... |
| CVE-2026-33704 | HIGH | 8.8 | 0.4% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arb... |
| CVE-2026-33702 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Ob... |
| CVE-2026-33618 | HIGH | 8.8 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray... |
| CVE-2026-40163 | HIGH | 8.2 | 0.3% | Apr 10, 2026 | Saltcorn is an extensible, open source, no-code database application builder. Prior to 1.4.5, 1.5.5, and 1.6.0-beta.4, t... |
| CVE-2026-40162 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugs... |
| CVE-2026-32931 | HIGH | 8.8 | 0.5% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability ... |
| CVE-2026-32930 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR)... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now