2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5977 | CRITICAL | 9.8 | 2.1% | Apr 9, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This impacts the function setWiFiBasicCfg of th... |
| CVE-2026-5447 | HIGH | 7.5 | 0.2% | Apr 9, 2026 | Heap buffer overflow in CertFromX509 via AuthorityKeyIdentifier size confusion. A heap buffer overflow occurs when conve... |
| CVE-2026-5446 | HIGH | 7.1 | 0.3% | Apr 9, 2026 | In wolfSSL, ARIA-GCM cipher suites used in TLS 1.2 and DTLS 1.2 reuse an identical 12-byte GCM nonce for every applicati... |
| CVE-2026-40109 | LOW | 3.1 | 0.1% | Apr 9, 2026 | Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prio... |
| CVE-2026-40107 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | SiYuan is a personal knowledge management system. Prior to 3.6.4, SiYuan configures Mermaid.js with securityLevel: "loos... |
| CVE-2026-40093 | HIGH | 8.1 | 0.3% | Apr 9, 2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In 1.3.0 and earlier, block timestam... |
| CVE-2026-35206 | MEDIUM | 4.4 | 0.2% | Apr 9, 2026 | Helm is a package manager for Charts for Kubernetes. In Helm versions <=3.20.1 and <=4.1.3, a specially crafted Chart wi... |
| CVE-2026-5976 | CRITICAL | 9.8 | 1.8% | Apr 9, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setStorageCfg of... |
| CVE-2026-5975 | CRITICAL | 9.8 | 1.8% | Apr 9, 2026 | A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. The impacted element is the function setDmzCfg ... |
| CVE-2026-5974 | CRITICAL | 9.8 | 2.2% | Apr 9, 2026 | A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The affected element is the function Bash.run in... |
| CVE-2026-5973 | CRITICAL | 9.8 | 2.3% | Apr 9, 2026 | A vulnerability was found in FoundationAgents MetaGPT up to 0.8.1. Impacted is the function get_mime_type of the file me... |
| CVE-2026-5972 | CRITICAL | 9.8 | 2.3% | Apr 9, 2026 | A vulnerability has been found in FoundationAgents MetaGPT up to 0.8.1. This issue affects the function Terminal.run_com... |
| CVE-2026-5194 | CRITICAL | 9.1 | 0.5% | Apr 9, 2026 | Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller... |
| CVE-2026-5187 | CRITICAL | 9.8 | 0.3% | Apr 9, 2026 | Two potential heap out-of-bounds write locations existed in DecodeObjectId() in wolfcrypt/src/asn.c. First, a bounds che... |
| CVE-2026-4436 | HIGH | 8.6 | 0.4% | Apr 9, 2026 | A low-privileged remote attacker can send Modbus packets to manipulate register values that are inputs to the odorant i... |
| CVE-2026-40089 | CRITICAL | 9.9 | 0.2% | Apr 9, 2026 | Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack da... |
| CVE-2026-40088 | CRITICAL | 9.6 | 0.4% | Apr 9, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are... |
| CVE-2026-40087 | MEDIUM | 5.3 | 0.3% | Apr 9, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-str... |
| CVE-2026-40077 | LOW | 3.1 | 0.2% | Apr 9, 2026 | Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied sys... |
| CVE-2026-39977 | MEDIUM | 6.3 | 0.3% | Apr 9, 2026 | flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key take... |
| CVE-2026-35577 | HIGH | 8.1 | 0.2% | Apr 9, 2026 | Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.... |
| CVE-2026-35063 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with r... |
| CVE-2026-34734 | HIGH | 7.8 | 0.2% | Apr 9, 2026 | HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utilit... |
| CVE-2026-34500 | MEDIUM | 6.5 | 0.5% | Apr 9, 2026 | CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Ap... |
| CVE-2026-34487 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apach... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now