2026 CVE Vulnerabilities
53,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32145 | HIGH | 7.5 | 0.6% | Apr 2, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via mul... |
| CVE-2026-5246 | HIGH | 8.1 | 0.6% | Apr 2, 2026 | A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of ... |
| CVE-2026-5245 | HIGH | 8.1 | 0.7% | Apr 2, 2026 | A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongo... |
| CVE-2026-33616 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpo... |
| CVE-2026-33614 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint du... |
| CVE-2026-33613 | HIGH | 8.8 | 0.5% | Apr 2, 2026 | Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulne... |
| CVE-2026-29138 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim ano... |
| CVE-2026-29135 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject san... |
| CVE-2026-29134 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass... |
| CVE-2026-29132 | HIGH | 7.5 | 0.3% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass ... |
| CVE-2026-29131 | HIGH | 7.5 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the ... |
| CVE-2026-0634 | HIGH | 7.8 | 0.5% | Apr 2, 2026 | Code execution in AssistFeedbackService of TECNO Pova7 Pro 5G on Android allows local apps to execute arbitrary code as ... |
| CVE-2026-5032 | HIGH | 7.5 | 1.0% | Apr 2, 2026 | The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.... |
| CVE-2026-0686 | HIGH | 7.2 | 0.3% | Apr 2, 2026 | The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5... |
| CVE-2026-5322 | HIGH | 7.3 | 0.3% | Apr 2, 2026 | A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69... |
| CVE-2026-4347 | HIGH | 8.1 | 1.3% | Apr 2, 2026 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via ... |
| CVE-2026-1540 | HIGH | 7.2 | 0.6% | Apr 2, 2026 | The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an at... |
| CVE-2026-5320 | HIGH | 7.3 | 0.4% | Apr 2, 2026 | A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality o... |
| CVE-2026-5317 | HIGH | 8.8 | 0.4% | Apr 2, 2026 | A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_... |
| CVE-2026-5315 | HIGH | 8.8 | 0.5% | Apr 2, 2026 | A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the l... |
| CVE-2026-21765 | HIGH | 7.8 | 0.1% | Apr 2, 2026 | HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys l... |
| CVE-2026-5314 | HIGH | 8.8 | 0.7% | Apr 1, 2026 | A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library st... |
| CVE-2026-32928 | HIGH | 8.4 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Op... |
| CVE-2026-32925 | HIGH | 8.4 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Open... |
| CVE-2026-3987 | HIGH | 7.2 | 0.6% | Apr 1, 2026 | A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authentica... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now