2026 CVE Vulnerabilities
45,099 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20884 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially... |
| CVE-2026-5735 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corr... |
| CVE-2026-5734 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Som... |
| CVE-2026-5731 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Th... |
| CVE-2026-28808 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protect... |
| CVE-2026-23818 | CRITICAL | 9.6 | 0.3% | Apr 7, 2026 | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Pre... |
| CVE-2026-22679 | CRITICAL | 9.8 | 21.5% | Apr 7, 2026 | Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability ... |
| CVE-2026-1114 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to t... |
| CVE-2026-0740 | CRITICAL | 9.8 | 54.3% | Apr 7, 2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val... |
| CVE-2026-35471 | CRITICAL | 9.8 | 0.7% | Apr 6, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal chec... |
| CVE-2026-35408 | CRITICAL | 9.3 | 0.2% | Apr 6, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sig... |
| CVE-2026-35393 | CRITICAL | 9.8 | 0.7% | Apr 6, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, the POST multipart upload directory not sanitized. Thi... |
| CVE-2026-35392 | CRITICAL | 9.8 | 0.7% | Apr 6, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, PUT upload in httpserver/updown.go has no path sanitiz... |
| CVE-2026-35459 | CRITICAL | 9.1 | 0.3% | Apr 6, 2026 | pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-s... |
| CVE-2026-35197 | CRITICAL | 9.8 | 0.3% | Apr 6, 2026 | dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would... |
| CVE-2026-35184 | CRITICAL | 9.8 | 0.4% | Apr 6, 2026 | EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/template... |
| CVE-2026-35178 | CRITICAL | 9.8 | 0.5% | Apr 6, 2026 | Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Fo... |
| CVE-2026-35171 | CRITICAL | 9.8 | 0.7% | Apr 6, 2026 | Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path t... |
| CVE-2026-35052 | CRITICAL | 9.8 | 0.6% | Apr 6, 2026 | D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3... |
| CVE-2026-35047 | CRITICAL | 9.8 | 0.6% | Apr 6, 2026 | Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allo... |
| CVE-2026-35044 | CRITICAL | 9.6 | 0.4% | Apr 6, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
| CVE-2026-35039 | CRITICAL | 9.1 | 0.2% | Apr 6, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuil... |
| CVE-2026-35035 | CRITICAL | 9 | 0.5% | Apr 6, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-35030 | CRITICAL | 9.4 | 0.5% | Apr 6, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authenti... |
| CVE-2026-34989 | CRITICAL | 9 | 0.3% | Apr 6, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now