2026 CVE Vulnerabilities
64,982 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41208 | HIGH | 8.8 | 0.6% | Apr 23, 2026 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @papercl... |
| CVE-2026-41206 | HIGH | 7.8 | 0.2% | Apr 23, 2026 | PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The... |
| CVE-2026-41200 | HIGH | 8.5 | 0.3% | Apr 23, 2026 | STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Infor... |
| CVE-2026-41197 | CRITICAL | 9.3 | 0.4% | Apr 23, 2026 | Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system,... |
| CVE-2026-41196 | CRITICAL | 10 | 0.4% | Apr 23, 2026 | Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to versio... |
| CVE-2026-41182 | MEDIUM | 5.3 | 0.2% | Apr 23, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScri... |
| CVE-2026-41180 | HIGH | 7.5 | 0.3% | Apr 23, 2026 | PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/... |
| CVE-2026-1923 | MEDIUM | 6.4 | 0.2% | Apr 23, 2026 | The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’... |
| CVE-2026-6878 | MEDIUM | 5.6 | 0.3% | Apr 23, 2026 | A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math... |
| CVE-2026-6874 | MEDIUM | 4.3 | 0.3% | Apr 23, 2026 | A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token ... |
| CVE-2026-5935 | CRITICAL | 9.8 | 0.3% | Apr 23, 2026 | IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated us... |
| CVE-2026-5926 | MEDIUM | 6.5 | 0.2% | Apr 23, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-4919 | MEDIUM | 4.8 | 0.2% | Apr 23, 2026 | IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative use... |
| CVE-2026-4918 | MEDIUM | 4.8 | 0.1% | Apr 23, 2026 | IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrat... |
| CVE-2026-4917 | MEDIUM | 4.9 | 0.4% | Apr 23, 2026 | IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker ... |
| CVE-2026-41179 | CRITICAL | 9.8 | 9.2% | Apr 23, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting i... |
| CVE-2026-41176 | CRITICAL | 9.8 | 34.7% | Apr 23, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC end... |
| CVE-2026-40062 | HIGH | 8.7 | 0.6% | Apr 23, 2026 | A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sen... |
| CVE-2026-3621 | MEDIUM | 5.9 | 0.3% | Apr 23, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnera... |
| CVE-2026-32679 | HIGH | 8.4 | 0.2% | Apr 23, 2026 | The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the... |
| CVE-2026-29198 | CRITICAL | 9.8 | 0.4% | Apr 23, 2026 | In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability c... |
| CVE-2026-1726 | MEDIUM | 4.8 | 0.2% | Apr 23, 2026 | IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthori... |
| CVE-2026-1352 | MEDIUM | 6.5 | 0.3% | Apr 23, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2026-1274 | MEDIUM | 4.9 | 0.3% | Apr 23, 2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access m... |
| CVE-2026-1272 | MEDIUM | 4.3 | 0.2% | Apr 23, 2026 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now