2026 CVE Vulnerabilities
45,093 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39958 | CRITICAL | 9.1 | 0.4% | Apr 9, 2026 | oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repos... |
| CVE-2026-30479 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitr... |
| CVE-2026-5445 | CRITICAL | 9.1 | 0.7% | Apr 9, 2026 | An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The looku... |
| CVE-2026-5443 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation... |
| CVE-2026-5442 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Represe... |
| CVE-2026-34184 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all file... |
| CVE-2026-34179 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | In Canonical LXD versions 4.12 through 6.7, the doCertificateUpdate function in lxd/certificates.go does not validate th... |
| CVE-2026-34178 | CRITICAL | 9.1 | 0.4% | Apr 9, 2026 | In Canonical LXD before 6.8, the backup import path validates project restrictions against backup/index.yaml in the supp... |
| CVE-2026-34177 | CRITICAL | 9.1 | 0.4% | Apr 9, 2026 | Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limit... |
| CVE-2026-5854 | CRITICAL | 9.8 | 17.5% | Apr 9, 2026 | A vulnerability was detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this issue is the function setWiFiEas... |
| CVE-2026-5853 | CRITICAL | 9.8 | 14.3% | Apr 9, 2026 | A security vulnerability has been detected in Totolink A7100RU 7.4cu.2313_b20191024. Affected by this vulnerability is t... |
| CVE-2026-5852 | CRITICAL | 9.8 | 14.3% | Apr 9, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. Affected is the function setIptvCfg of the file... |
| CVE-2026-5851 | CRITICAL | 9.8 | 14.1% | Apr 9, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setUPnPCfg of th... |
| CVE-2026-5850 | CRITICAL | 9.8 | 16.0% | Apr 9, 2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the ... |
| CVE-2026-5849 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown function of the component... |
| CVE-2026-5841 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function R7WebsSecurityHandler of ... |
| CVE-2026-1830 | CRITICAL | 9.8 | 3.1% | Apr 9, 2026 | The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1... |
| CVE-2026-3199 | CRITICAL | 9.4 | 0.5% | Apr 8, 2026 | A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an a... |
| CVE-2026-5902 | CRITICAL | 9.8 | 0.2% | Apr 8, 2026 | Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the rende... |
| CVE-2026-5874 | CRITICAL | 9.6 | 0.3% | Apr 8, 2026 | Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to en... |
| CVE-2026-40035 | CRITICAL | 9.3 | 0.6% | Apr 8, 2026 | Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mo... |
| CVE-2026-39892 | CRITICAL | 9.8 | 0.7% | Apr 8, 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to b... |
| CVE-2026-39890 | CRITICAL | 9.8 | 0.6% | Apr 8, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml li... |
| CVE-2026-39888 | CRITICAL | 9.9 | 0.5% | Apr 8, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults... |
| CVE-2026-39429 | CRITICAL | 9.1 | 0.4% | Apr 8, 2026 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now