2026 CVE Vulnerabilities
45,092 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40154 | CRITICAL | 9.6 | 0.3% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted e... |
| CVE-2026-40114 | CRITICAL | 10 | 0.3% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in... |
| CVE-2026-33784 | CRITICAL | 9.8 | 0.5% | Apr 9, 2026 | A Use of Default Password vulnerability in the Juniper Networks Support Insights (JSI) Virtual Lightweight Collector... |
| CVE-2026-5978 | CRITICAL | 9.8 | 1.8% | Apr 9, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setWiFiAcl... |
| CVE-2026-5977 | CRITICAL | 9.8 | 2.1% | Apr 9, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of th... |
| CVE-2026-5976 | CRITICAL | 9.8 | 1.8% | Apr 9, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of... |
| CVE-2026-5975 | CRITICAL | 9.8 | 1.8% | Apr 9, 2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg ... |
| CVE-2026-5974 | CRITICAL | 9.8 | 2.2% | Apr 9, 2026 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in... |
| CVE-2026-5973 | CRITICAL | 9.8 | 2.3% | Apr 9, 2026 | A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file me... |
| CVE-2026-5972 | CRITICAL | 9.8 | 2.3% | Apr 9, 2026 | A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_com... |
| CVE-2026-5194 | CRITICAL | 9.1 | 0.5% | Apr 9, 2026 | Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller... |
| CVE-2026-5187 | CRITICAL | 9.8 | 0.3% | Apr 9, 2026 | Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds che... |
| CVE-2026-40089 | CRITICAL | 9.9 | 0.2% | Apr 9, 2026 | Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack da... |
| CVE-2026-40088 | CRITICAL | 9.6 | 0.4% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are... |
| CVE-2026-29145 | CRITICAL | 9.1 | 0.7% | Apr 9, 2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apac... |
| CVE-2026-39912 | CRITICAL | 9.1 | 0.6% | Apr 9, 2026 | V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWi... |
| CVE-2026-34987 | CRITICAL | 9.9 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseli... |
| CVE-2026-34971 | CRITICAL | 9 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilatio... |
| CVE-2026-31170 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm... |
| CVE-2026-28205 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an ... |
| CVE-2026-5971 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fi... |
| CVE-2026-5970 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the co... |
| CVE-2026-39987 | CRITICAL | 9.8 | 95.6% | Apr 9, 2026 | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket e... |
| CVE-2026-5962 | CRITICAL | 9.8 | 0.5% | Apr 9, 2026 | A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction o... |
| CVE-2026-39962 | CRITICAL | 9.6 | 0.3% | Apr 9, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special ele... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now