2026 CVE Vulnerabilities
53,128 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35641 | HIGH | 7.8 | 0.1% | Apr 10, 2026 | OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that ... |
| CVE-2026-35621 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validat... |
| CVE-2026-35602 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the Vikunja file import endpoint uses th... |
| CVE-2026-35597 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the TOTP failed-attempt lockout mechanis... |
| CVE-2026-35595 | HIGH | 8.3 | 0.3% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CanUpdate check at pkg/models/projec... |
| CVE-2026-40224 | HIGH | 7.3 | 0.1% | Apr 10, 2026 | In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach ... |
| CVE-2026-34481 | HIGH | 7.5 | 0.6% | Apr 10, 2026 | Apache Log4j's JsonTemplateLayout https://logging.apache.org/log4j/2.x/manual/json-template-layout.html , in versions u... |
| CVE-2026-34480 | HIGH | 7.5 | 0.9% | Apr 10, 2026 | Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to an... |
| CVE-2026-34479 | HIGH | 7.5 | 0.5% | Apr 10, 2026 | The Log4j1XmlLayout from the Apache Log4j 1-to-Log4j 2 bridge fails to escape characters forbidden by the XML 1.0 standa... |
| CVE-2026-34478 | HIGH | 7.5 | 0.8% | Apr 10, 2026 | Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions ... |
| CVE-2026-29002 | HIGH | 8.6 | 0.4% | Apr 10, 2026 | CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin ... |
| CVE-2026-23782 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated us... |
| CVE-2026-23780 | HIGH | 8.8 | 0.4% | Apr 10, 2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug... |
| CVE-2026-6069 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker... |
| CVE-2026-40217 | HIGH | 8.8 | 6.5% | Apr 10, 2026 | LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/t... |
| CVE-2026-33092 | HIGH | 7.8 | 0.2% | Apr 10, 2026 | Local privilege escalation due to improper handling of environment variables. The following products are affected: Acron... |
| CVE-2026-5777 | HIGH | 8.7 | 0.3% | Apr 10, 2026 | This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service ov... |
| CVE-2026-39304 | HIGH | 7.5 | 0.9% | Apr 10, 2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. A... |
| CVE-2026-4162 | HIGH | 7.1 | 0.3% | Apr 10, 2026 | The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. Th... |
| CVE-2026-6038 | HIGH | 7.3 | 0.3% | Apr 10, 2026 | A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function... |
| CVE-2026-6037 | HIGH | 7.3 | 0.3% | Apr 10, 2026 | A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function... |
| CVE-2026-6036 | HIGH | 7.3 | 0.3% | Apr 10, 2026 | A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown fu... |
| CVE-2026-33456 | HIGH | 7.6 | 0.2% | Apr 10, 2026 | Livestatus injection in the notification test mode in Checkmk <2.5.0b4 and <2.4.0p26 allows an authenticated user with a... |
| CVE-2026-6031 | HIGH | 7.3 | 0.4% | Apr 10, 2026 | A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the ... |
| CVE-2026-5525 | HIGH | 7.8 | 0.2% | Apr 10, 2026 | A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now