2026 CVE Vulnerabilities
45,110 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34559 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-4101 | CRITICAL | 9.8 | 0.4% | Apr 1, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-34873 | CRITICAL | 9.1 | 0.2% | Apr 1, 2026 | An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session... |
| CVE-2026-34529 | CRITICAL | 9 | 0.3% | Apr 1, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-34528 | CRITICAL | 9.8 | 0.7% | Apr 1, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-34520 | CRITICAL | 9.1 | 0.5% | Apr 1, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (t... |
| CVE-2026-34872 | CRITICAL | 9.1 | 0.2% | Apr 1, 2026 | An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory... |
| CVE-2026-34456 | CRITICAL | 9.8 | 0.5% | Apr 1, 2026 | Reviactyl is an open-source game server management panel built using Laravel, React, FilamentPHP, Vite, and Go. From ver... |
| CVE-2026-34875 | CRITICAL | 9.8 | 0.4% | Apr 1, 2026 | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key exp... |
| CVE-2026-34751 | CRITICAL | 9.1 | 0.3% | Apr 1, 2026 | Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and... |
| CVE-2026-34236 | CRITICAL | 9.8 | 0.2% | Apr 1, 2026 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in app... |
| CVE-2026-34159 | CRITICAL | 9.8 | 1.1% | Apr 1, 2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor()... |
| CVE-2026-34072 | CRITICAL | 9.8 | 0.4% | Apr 1, 2026 | Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs... |
| CVE-2026-33990 | CRITICAL | 9.1 | 0.3% | Apr 1, 2026 | Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, D... |
| CVE-2026-30643 | CRITICAL | 9.8 | 0.6% | Apr 1, 2026 | An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module u... |
| CVE-2026-20160 | CRITICAL | 9.8 | 0.9% | Apr 1, 2026 | A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to... |
| CVE-2026-20093 | CRITICAL | 9.8 | 1.0% | Apr 1, 2026 | A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unau... |
| CVE-2026-31027 | CRITICAL | 9.8 | 0.6% | Apr 1, 2026 | TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste... |
| CVE-2026-34430 | CRITICAL | 9.6 | 0.4% | Apr 1, 2026 | ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that al... |
| CVE-2026-29014 | CRITICAL | 9.8 | 39.7% | Apr 1, 2026 | MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at... |
| CVE-2026-4370 | CRITICAL | 10 | 0.4% | Apr 1, 2026 | A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the inter... |
| CVE-2026-5257 | CRITICAL | 9.8 | 0.3% | Apr 1, 2026 | A vulnerability has been found in code-projects Simple Laundry System 1.0. This issue affects some unknown processing of... |
| CVE-2026-5256 | CRITICAL | 9.8 | 0.3% | Apr 1, 2026 | A flaw has been found in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /m... |
| CVE-2026-5290 | CRITICAL | 9.6 | 0.2% | Apr 1, 2026 | Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the... |
| CVE-2026-5289 | CRITICAL | 9.6 | 0.3% | Apr 1, 2026 | Use after free in Navigation in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now