2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40037 | HIGH | 7.1 | 0.2% | Apr 8, 2026 | OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that ... |
| CVE-2026-40036 | HIGH | 8.7 | 0.5% | Apr 8, 2026 | Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote a... |
| CVE-2026-40035 | CRITICAL | 9.3 | 0.6% | Apr 8, 2026 | Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mo... |
| CVE-2026-40032 | HIGH | 8.5 | 0.7% | Apr 8, 2026 | UAC (Unix-like Artifacts Collector) before 3.3.0-rc1 contains a command injection vulnerability in the placeholder subst... |
| CVE-2026-40031 | HIGH | 8.5 | 0.1% | Apr 8, 2026 | MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking acr... |
| CVE-2026-40030 | HIGH | 8.4 | 0.8% | Apr 8, 2026 | parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is ... |
| CVE-2026-40029 | HIGH | 7.8 | 0.8% | Apr 8, 2026 | parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsa... |
| CVE-2026-40028 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allow... |
| CVE-2026-40027 | HIGH | 8.4 | 0.2% | Apr 8, 2026 | ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.p... |
| CVE-2026-40026 | HIGH | 7.1 | 0.1% | Apr 8, 2026 | The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the pa... |
| CVE-2026-40025 | MEDIUM | 6.1 | 0.1% | Apr 8, 2026 | The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where th... |
| CVE-2026-40024 | HIGH | 7.1 | 0.2% | Apr 8, 2026 | The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write fi... |
| CVE-2026-39901 | MEDIUM | 5.7 | 0.3% | Apr 8, 2026 | monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity f... |
| CVE-2026-5805 | HIGH | 7.3 | 0.3% | Apr 8, 2026 | A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of... |
| CVE-2026-5803 | MEDIUM | 6.3 | 0.2% | Apr 8, 2026 | A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The aff... |
| CVE-2026-5451 | MEDIUM | 6.4 | 0.2% | Apr 8, 2026 | The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-trac... |
| CVE-2026-5436 | HIGH | 8.1 | 1.1% | Apr 8, 2026 | The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1.... |
| CVE-2026-39892 | CRITICAL | 9.8 | 0.7% | Apr 8, 2026 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to b... |
| CVE-2026-39891 | HIGH | 8.8 | 0.6% | Apr 8, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like... |
| CVE-2026-39890 | CRITICAL | 9.8 | 0.6% | Apr 8, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml li... |
| CVE-2026-39889 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI expo... |
| CVE-2026-39888 | CRITICAL | 9.9 | 0.5% | Apr 8, 2026 | PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults... |
| CVE-2026-39885 | HIGH | 7.5 | 0.3% | Apr 8, 2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi libr... |
| CVE-2026-39883 | HIGH | 7 | 0.3% | Apr 8, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed th... |
| CVE-2026-39882 | MEDIUM | 5.3 | 0.2% | Apr 8, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/log... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now