2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5971 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fi... |
| CVE-2026-5970 | CRITICAL | 9.8 | 0.4% | Apr 9, 2026 | A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the co... |
| CVE-2026-5329 | MEDIUM | 6.5 | 0.4% | Apr 9, 2026 | Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring... |
| CVE-2026-40072 | HIGH | 7.2 | 0.2% | Apr 9, 2026 | web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web... |
| CVE-2026-40071 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /j... |
| CVE-2026-40070 | HIGH | 8.1 | 0.1% | Apr 9, 2026 | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certi... |
| CVE-2026-40069 | HIGH | 7.5 | 0.3% | Apr 9, 2026 | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection o... |
| CVE-2026-39987 | CRITICAL | 9.8 | 95.6% | Apr 9, 2026 | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket e... |
| CVE-2026-39985 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-39983 | HIGH | 8.6 | 2.2% | Apr 9, 2026 | basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n)... |
| CVE-2026-39981 | HIGH | 8.8 | 1.3% | Apr 9, 2026 | AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities ext... |
| CVE-2026-39980 | HIGH | 7.2 | 0.5% | Apr 9, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the... |
| CVE-2026-39961 | MEDIUM | 4.9 | 0.4% | Apr 9, 2026 | Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.3... |
| CVE-2026-39911 | HIGH | 8.8 | 0.5% | Apr 9, 2026 | Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerab... |
| CVE-2026-39315 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documen... |
| CVE-2026-35207 | MEDIUM | 5.4 | 0.1% | Apr 9, 2026 | dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-contr... |
| CVE-2026-30478 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalat... |
| CVE-2026-1584 | HIGH | 7.5 | 1.3% | Apr 9, 2026 | A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially cra... |
| CVE-2026-5962 | CRITICAL | 9.8 | 0.5% | Apr 9, 2026 | A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction o... |
| CVE-2026-5961 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects u... |
| CVE-2026-40046 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for... |
| CVE-2026-39976 | HIGH | 7.1 | 0.3% | Apr 9, 2026 | Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Byp... |
| CVE-2026-39974 | HIGH | 8.5 | 0.3% | Apr 9, 2026 | n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node docum... |
| CVE-2026-39972 | HIGH | 7.1 | 0.3% | Apr 9, 2026 | Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior ... |
| CVE-2026-39962 | CRITICAL | 9.6 | 0.3% | Apr 9, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special ele... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now