2026 CVE Vulnerabilities
45,103 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34977 | CRITICAL | 9.8 | 0.8% | Apr 6, 2026 | Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user ... |
| CVE-2026-34976 | CRITICAL | 10 | 0.5% | Apr 6, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from... |
| CVE-2026-34841 | CRITICAL | 9.8 | 0.2% | Apr 6, 2026 | Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack ... |
| CVE-2026-34950 | CRITICAL | 9.1 | 0.2% | Apr 6, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-... |
| CVE-2026-34444 | CRITICAL | 10 | 0.6% | Apr 6, 2026 | Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently ap... |
| CVE-2026-34208 | CRITICAL | 10 | 0.6% | Apr 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for... |
| CVE-2026-5663 | CRITICAL | 9.8 | 1.7% | Apr 6, 2026 | A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEn... |
| CVE-2026-31151 | CRITICAL | 9.8 | 0.4% | Apr 6, 2026 | An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the appl... |
| CVE-2026-31059 | CRITICAL | 9.8 | 0.9% | Apr 6, 2026 | A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-18... |
| CVE-2026-26263 | CRITICAL | 9.8 | 8.7% | Apr 6, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based bli... |
| CVE-2026-31405 | CRITICAL | 9.8 | 0.5% | Apr 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension hea... |
| CVE-2026-5584 | CRITICAL | 9.8 | 0.4% | Apr 5, 2026 | A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file s... |
| CVE-2026-5574 | CRITICAL | 9.1 | 0.5% | Apr 5, 2026 | A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function del... |
| CVE-2026-5573 | CRITICAL | 9.8 | 0.5% | Apr 5, 2026 | A weakness has been identified in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. This impacts an unknown function of the ... |
| CVE-2026-5570 | CRITICAL | 9.8 | 0.6% | Apr 5, 2026 | A vulnerability was determined in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. The affected element is the function ind... |
| CVE-2026-5569 | CRITICAL | 9.8 | 0.4% | Apr 5, 2026 | A vulnerability was found in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Impacted is an unknown function of the file /... |
| CVE-2026-5562 | CRITICAL | 9.8 | 0.6% | Apr 5, 2026 | A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /... |
| CVE-2026-5526 | CRITICAL | 9.8 | 0.4% | Apr 4, 2026 | A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerabil... |
| CVE-2026-35616 | CRITICAL | 9.8 | 88.9% | Apr 4, 2026 | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated atta... |
| CVE-2026-34955 | CRITICAL | 10 | 0.4% | Apr 4, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, SubprocessSandbox in all modes (BASIC, STRICT, NETWORK... |
| CVE-2026-34775 | CRITICAL | 9.8 | 0.3% | Apr 4, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version... |
| CVE-2026-34953 | CRITICAL | 9.1 | 0.4% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validate_token() returns True for any tok... |
| CVE-2026-34952 | CRITICAL | 9.1 | 0.4% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connect... |
| CVE-2026-34938 | CRITICAL | 10 | 1.3% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-contr... |
| CVE-2026-34937 | CRITICAL | 9.8 | 0.5% | Apr 3, 2026 | PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command s... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now