2026 CVE Vulnerabilities
65,368 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5985 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A security flaw has been discovered in code-projects Simple IT Discussion Forum 1.0. The affected element is an unknown ... |
| CVE-2026-5507 | MEDIUM | 4 | 0.2% | Apr 9, 2026 | When restoring a session from cache, a pointer from the serialized session data is used in a free operation without vali... |
| CVE-2026-5504 | MEDIUM | 5.3 | 0.1% | Apr 9, 2026 | A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover plaintext through repe... |
| CVE-2026-5503 | CRITICAL | 9.1 | 0.4% | Apr 9, 2026 | In TLSX_EchChangeSNI, the ctx->extensions branch set extensions unconditionally even when TLSX_Find returned NULL. This ... |
| CVE-2026-5295 | HIGH | 8 | 0.2% | Apr 9, 2026 | A stack buffer overflow exists in wolfSSL's PKCS7 implementation in the wc_PKCS7_DecryptOri() function in wolfcrypt/src/... |
| CVE-2026-34424 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected throu... |
| CVE-2026-5984 | HIGH | 8.8 | 0.8% | Apr 9, 2026 | A vulnerability was identified in D-Link DIR-605L 2.13B01. Impacted is the function formSetLog of the file /goform/formS... |
| CVE-2026-5983 | HIGH | 8.8 | 0.7% | Apr 9, 2026 | A vulnerability was determined in D-Link DIR-605L 2.13B01. This issue affects the function formSetDDNS of the file /gofo... |
| CVE-2026-5982 | HIGH | 8.8 | 0.7% | Apr 9, 2026 | A vulnerability was found in D-Link DIR-605L 2.13B01. This vulnerability affects the function formAdvNetwork of the file... |
| CVE-2026-5981 | HIGH | 8.8 | 0.7% | Apr 9, 2026 | A vulnerability has been found in D-Link DIR-605L 2.13B01. This affects the function formAdvFirewall of the file /goform... |
| CVE-2026-5778 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | Integer underflow in wolfSSL packet sniffer <= 5.9.0 allows an attacker to cause a program crash in the AEAD decryption ... |
| CVE-2026-5772 | MEDIUM | 5.3 | 0.2% | Apr 9, 2026 | A 1-byte stack buffer over-read was identified in the MatchDomainName function (src/internal.c) during wildcard hostname... |
| CVE-2026-5264 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1.3 ACK message that ... |
| CVE-2026-5263 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | URI nameConstraints from constrained intermediate CAs are parsed but not enforced during certificate chain verification ... |
| CVE-2026-40154 | CRITICAL | 9.6 | 0.3% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted e... |
| CVE-2026-40153 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os... |
| CVE-2026-40152 | MEDIUM | 5.3 | 0.3% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directo... |
| CVE-2026-40151 | MEDIUM | 5.3 | 0.8% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents end... |
| CVE-2026-40150 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_c... |
| CVE-2026-40149 | HIGH | 7.3 | 0.2% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the gateway's /api/approval/allow-list endpoint permits unaut... |
| CVE-2026-40148 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registr... |
| CVE-2026-40117 | HIGH | 7.5 | 0.2% | Apr 9, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbi... |
| CVE-2026-40116 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /media-stream WebSocket endpoint in PraisonAI's call modu... |
| CVE-2026-40115 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the e... |
| CVE-2026-40114 | CRITICAL | 10 | 0.3% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now