2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39881 | HIGH | 7.8 | 0.6% | Apr 8, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans ... |
| CVE-2026-39860 | HIGH | 8.4 | 0.2% | Apr 8, 2026 | Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary ove... |
| CVE-2026-39844 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path... |
| CVE-2026-39429 | CRITICAL | 9.1 | 0.4% | Apr 8, 2026 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t... |
| CVE-2026-39416 | MEDIUM | 6.1 | 0.2% | Apr 8, 2026 | AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a store... |
| CVE-2026-39415 | MEDIUM | 4.3 | 0.3% | Apr 8, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, ... |
| CVE-2026-39414 | MEDIUM | 6.5 | 0.5% | Apr 8, 2026 | MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-... |
| CVE-2026-5802 | HIGH | 7.3 | 1.7% | Apr 8, 2026 | A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP ... |
| CVE-2026-39880 | MEDIUM | 4.9 | 0.2% | Apr 8, 2026 | Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the H... |
| CVE-2026-39864 | MEDIUM | 4.9 | 0.3% | Apr 8, 2026 | Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in ... |
| CVE-2026-39863 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds ... |
| CVE-2026-39862 | HIGH | 8.8 | 0.6% | Apr 8, 2026 | Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted... |
| CVE-2026-39859 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 d... |
| CVE-2026-39413 | MEDIUM | 6.5 | 0.2% | Apr 8, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a J... |
| CVE-2026-39412 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural f... |
| CVE-2026-39411 | HIGH | 7.1 | 0.1% | Apr 8, 2026 | LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ... |
| CVE-2026-39362 | HIGH | 7.1 | 0.2% | Apr 8, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is e... |
| CVE-2026-35525 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %},... |
| CVE-2026-35479 | MEDIUM | 4.7 | 0.2% | Apr 8, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permi... |
| CVE-2026-35478 | HIGH | 8.1 | 0.3% | Apr 8, 2026 | InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user c... |
| CVE-2026-35477 | CRITICAL | 9.9 | 0.3% | Apr 8, 2026 | InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PA... |
| CVE-2026-35476 | MEDIUM | 4.3 | 0.1% | Apr 8, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can el... |
| CVE-2026-23869 | HIGH | 7.5 | 1.6% | Apr 8, 2026 | A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-... |
| CVE-2026-39851 | MEDIUM | 4.3 | 0.2% | Apr 8, 2026 | Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange... |
| CVE-2026-35455 | MEDIUM | 5.4 | 0.2% | Apr 8, 2026 | immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now