2026 CVE Vulnerabilities
45,110 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5368 | CRITICAL | 9.8 | 0.3% | Apr 2, 2026 | A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of t... |
| CVE-2026-34877 | CRITICAL | 9.8 | 0.4% | Apr 2, 2026 | An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of seriali... |
| CVE-2026-33950 | CRITICAL | 9.4 | 0.4% | Apr 2, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a... |
| CVE-2026-25212 | CRITICAL | 9.9 | 0.3% | Apr 2, 2026 | An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileg... |
| CVE-2026-33746 | CRITICAL | 9.8 | 0.3% | Apr 2, 2026 | Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWT... |
| CVE-2026-35002 | CRITICAL | 9.8 | 0.8% | Apr 2, 2026 | Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that al... |
| CVE-2026-32871 | CRITICAL | 10 | 1.0% | Apr 2, 2026 | FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP expos... |
| CVE-2026-5334 | CRITICAL | 9.8 | 0.4% | Apr 2, 2026 | A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file... |
| CVE-2026-5333 | CRITICAL | 9.8 | 2.7% | Apr 2, 2026 | A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown pro... |
| CVE-2026-2699 | CRITICAL | 9.8 | 49.4% | Apr 2, 2026 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted config... |
| CVE-2026-33615 | CRITICAL | 9.1 | 0.4% | Apr 2, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint du... |
| CVE-2026-29143 | CRITICAL | 9.1 | 0.3% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted... |
| CVE-2026-29139 | CRITICAL | 9.8 | 0.3% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to re... |
| CVE-2026-29133 | CRITICAL | 9.1 | 0.2% | Apr 2, 2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match th... |
| CVE-2026-5244 | CRITICAL | 9.8 | 0.7% | Apr 2, 2026 | A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mo... |
| CVE-2026-34571 | CRITICAL | 9 | 0.4% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34569 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34568 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34567 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34566 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34565 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34564 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34563 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34562 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34560 | CRITICAL | 9 | 0.4% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now