2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39959 | HIGH | 7.1 | 0.1% | Apr 9, 2026 | Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to m... |
| CVE-2026-39958 | CRITICAL | 9.1 | 0.4% | Apr 9, 2026 | oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repos... |
| CVE-2026-39957 | MEDIUM | 4.3 | 0.2% | Apr 9, 2026 | Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController:... |
| CVE-2026-39943 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revis... |
| CVE-2026-39942 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id}... |
| CVE-2026-39856 | MEDIUM | 5.5 | 0.1% | Apr 9, 2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulne... |
| CVE-2026-39855 | MEDIUM | 5.5 | 0.1% | Apr 9, 2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulner... |
| CVE-2026-30479 | CRITICAL | 9.1 | 0.3% | Apr 9, 2026 | A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitr... |
| CVE-2026-5960 | MEDIUM | 4.3 | 0.3% | Apr 9, 2026 | A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of th... |
| CVE-2026-4878 | HIGH | 7 | — | Apr 9, 2026 | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition... |
| CVE-2026-39941 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied inpu... |
| CVE-2026-39853 | HIGH | 7.8 | 0.2% | Apr 9, 2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vul... |
| CVE-2026-39843 | HIGH | 7.7 | 0.2% | Apr 9, 2026 | Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw ... |
| CVE-2026-39398 | — | — | — | Apr 9, 2026 | Rejected reason: The affected product and advisory are not public. |
| CVE-2026-35205 | HIGH | 7.8 | 0.2% | Apr 9, 2026 | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (... |
| CVE-2026-35204 | HIGH | 8.6 | 0.2% | Apr 9, 2026 | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installe... |
| CVE-2026-35041 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in... |
| CVE-2026-35040 | MEDIUM | 5.3 | 0.4% | Apr 9, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in... |
| CVE-2026-34020 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint us... |
| CVE-2026-33266 | HIGH | 7.5 | 0.2% | Apr 9, 2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set ... |
| CVE-2026-33005 | MEDIUM | 4.3 | 0.4% | Apr 9, 2026 | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web se... |
| CVE-2026-5959 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is ... |
| CVE-2026-5445 | CRITICAL | 9.1 | 0.7% | Apr 9, 2026 | An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The looku... |
| CVE-2026-5444 | HIGH | 7.1 | 0.2% | Apr 9, 2026 | A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image e... |
| CVE-2026-5443 | CRITICAL | 9.8 | 0.6% | Apr 9, 2026 | A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now