2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39399 | CRITICAL | 9.6 | 0.5% | Apr 14, 2026 | NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend... |
| CVE-2026-39387 | HIGH | 7.2 | 0.7% | Apr 14, 2026 | BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. V... |
| CVE-2026-35589 | CRITICAL | 9.3 | 0.2% | Apr 14, 2026 | nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerabili... |
| CVE-2026-35034 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability... |
| CVE-2026-35033 | CRITICAL | 9.1 | 0.3% | Apr 14, 2026 | Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file... |
| CVE-2026-35032 | HIGH | 8.1 | 0.3% | Apr 14, 2026 | Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the Live... |
| CVE-2026-35031 | HIGH | 8.8 | 0.8% | Apr 14, 2026 | Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subt... |
| CVE-2026-34457 | CRITICAL | 9.1 | 0.5% | Apr 14, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a ... |
| CVE-2026-34454 | LOW | 3.5 | 0.2% | Apr 14, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p... |
| CVE-2026-33414 | HIGH | 7.8 | 0.6% | Apr 14, 2026 | Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerab... |
| CVE-2026-33023 | HIGH | 7.8 | 0.3% | Apr 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built w... |
| CVE-2026-33021 | HIGH | 7.3 | 0.2% | Apr 14, 2026 | libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-af... |
| CVE-2026-27301 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead ... |
| CVE-2026-27300 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could... |
| CVE-2026-27299 | MEDIUM | 6.3 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead ... |
| CVE-2026-27298 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confus... |
| CVE-2026-27297 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha... |
| CVE-2026-27296 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha... |
| CVE-2026-27295 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in a... |
| CVE-2026-27294 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted ... |
| CVE-2026-27293 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resul... |
| CVE-2026-27292 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitra... |
| CVE-2026-27290 | HIGH | 8.6 | 0.2% | Apr 14, 2026 | Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow att... |
| CVE-2026-40291 | HIGH | 8.8 | 0.3% | Apr 14, 2026 | Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object mod... |
| CVE-2026-39907 | CRITICAL | 10 | 0.6% | Apr 14, 2026 | Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now