2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5437 | HIGH | 7.5 | 0.6% | Apr 9, 2026 | An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malf... |
| CVE-2026-4116 | HIGH | 7.2 | 0.4% | Apr 9, 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user t... |
| CVE-2026-4113 | HIGH | 7.2 | 0.4% | Apr 9, 2026 | An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to ... |
| CVE-2026-4112 | HIGH | 7.2 | 0.6% | Apr 9, 2026 | Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series applian... |
| CVE-2026-34578 | HIGH | 8.2 | 0.4% | Apr 9, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.6, OPNsense's LDAP authentication connector pas... |
| CVE-2026-4660 | HIGH | 7.5 | 0.6% | Apr 9, 2026 | HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operatio... |
| CVE-2026-34185 | HIGH | 8.8 | 0.3% | Apr 9, 2026 | AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in pla... |
| CVE-2026-5844 | HIGH | 7.3 | 5.1% | Apr 9, 2026 | A vulnerability was found in D-Link DIR-882 1.01B02. Impacted is the function sprintf of the file prog.cgi of the compon... |
| CVE-2026-5842 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A security vulnerability has been detected in decolua 9router up to 0.3.47. The impacted element is an unknown function ... |
| CVE-2026-5837 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A vulnerability was found in PHPGurukul News Portal Project 4.1. This affects an unknown part of the file /news-details.... |
| CVE-2026-5832 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A weakness has been identified in atototo api-lab-mcp up to 0.2.1. This affects the function analyze_api_spec/generate_t... |
| CVE-2026-5830 | HIGH | 8.8 | 0.6% | Apr 9, 2026 | A vulnerability was identified in Tenda AC15 15.03.05.18. This affects the function websGetVar of the file /goform/SysTo... |
| CVE-2026-5829 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A vulnerability was determined in code-projects Simple IT Discussion Forum 1.0. The impacted element is an unknown funct... |
| CVE-2026-5828 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A vulnerability was found in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown function o... |
| CVE-2026-4326 | HIGH | 8.8 | 0.6% | Apr 9, 2026 | The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and in... |
| CVE-2026-5827 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the f... |
| CVE-2026-5824 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A security vulnerability has been detected in code-projects Simple Laundry System 1.0. This affects an unknown part of t... |
| CVE-2026-5815 | HIGH | 8.8 | 0.5% | Apr 9, 2026 | A vulnerability was detected in D-Link DIR-645 1.01/1.02/1.03. Impacted is the function hedwigcgi_main of the file /cgi-... |
| CVE-2026-5814 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A security vulnerability has been detected in PHPGurukul Online Course Registration 3.1. This issue affects some unknown... |
| CVE-2026-5813 | HIGH | 7.3 | 0.3% | Apr 8, 2026 | A weakness has been identified in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of ... |
| CVE-2026-5173 | HIGH | 8.5 | 0.4% | Apr 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and... |
| CVE-2026-1092 | HIGH | 7.5 | 0.6% | Apr 8, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.8.9, 18.9 before 18.9.5, and ... |
| CVE-2026-5915 | HIGH | 8.1 | 0.2% | Apr 8, 2026 | Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to... |
| CVE-2026-5914 | HIGH | 8.8 | 0.2% | Apr 8, 2026 | Type Confusion in CSS in Google Chrome prior to 147.0.7727.55 allowed an attacker who convinced a user to install a mali... |
| CVE-2026-5913 | HIGH | 8.1 | 0.2% | Apr 8, 2026 | Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bound... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now