2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40336 | LOW | 2.4 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack... |
| CVE-2026-40334 | LOW | 3.5 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exi... |
| CVE-2026-35402 | LOW | 2.3 | 0.3% | Apr 17, 2026 | mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the ... |
| CVE-2026-6493 | LOW | 3.5 | 0.3% | Apr 17, 2026 | A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[lo... |
| CVE-2026-6486 | LOW | 3.5 | 0.2% | Apr 17, 2026 | A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/app... |
| CVE-2026-40263 | LOW | 3.7 | 0.2% | Apr 17, 2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt pa... |
| CVE-2026-41080 | LOW | 2.9 | 0.4% | Apr 16, 2026 | libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. |
| CVE-2026-3155 | LOW | 3.1 | 0.3% | Apr 16, 2026 | The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and... |
| CVE-2026-40947 | LOW | 2.9 | 0.1% | Apr 16, 2026 | Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search... |
| CVE-2026-6313 | LOW | 3.1 | 0.2% | Apr 15, 2026 | Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compr... |
| CVE-2026-6312 | LOW | 3.1 | 0.2% | Apr 15, 2026 | Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had ... |
| CVE-2026-33877 | LOW | 3.7 | 0.4% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-chann... |
| CVE-2026-21727 | LOW | 3.3 | 0.2% | Apr 15, 2026 | A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records.... |
| CVE-2026-33212 | LOW | 3.1 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending... |
| CVE-2026-27769 | LOW | 2.7 | 0.2% | Apr 15, 2026 | Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Wor... |
| CVE-2026-34454 | LOW | 3.5 | 0.2% | Apr 14, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p... |
| CVE-2026-27308 | LOW | 2.4 | 2.6% | Apr 14, 2026 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ... |
| CVE-2026-27307 | LOW | 2.4 | 2.9% | Apr 14, 2026 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ... |
| CVE-2026-27316 | LOW | 2.7 | 0.3% | Apr 14, 2026 | A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all ... |
| CVE-2026-37602 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/use... |
| CVE-2026-37601 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/app... |
| CVE-2026-37600 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/app... |
| CVE-2026-37598 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to arbitrary code execution (RCE) via /scheduler/... |
| CVE-2026-37597 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
| CVE-2026-37596 | LOW | 2.7 | 0.2% | Apr 14, 2026 | SourceCodester Online Employees Work From Home Attendance System v1.0 is vulnerable to SQL Injection in the file /wfh_at... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now