2026 CVE Vulnerabilities
65,684 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28390 | HIGH | 7.5 | 1.0% | Apr 7, 2026 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer de... |
| CVE-2026-28389 | HIGH | 7.5 | 1.0% | Apr 7, 2026 | Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer derefe... |
| CVE-2026-28388 | HIGH | 7.5 | 1.1% | Apr 7, 2026 | Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference mi... |
| CVE-2026-28387 | HIGH | 8.1 | 0.8% | Apr 7, 2026 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with u... |
| CVE-2026-28386 | HIGH | 7.5 | 0.3% | Apr 7, 2026 | Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigg... |
| CVE-2026-39401 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processe... |
| CVE-2026-39400 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user ... |
| CVE-2026-39397 | CRITICAL | 9.8 | 0.4% | Apr 7, 2026 | @delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/... |
| CVE-2026-35533 | HIGH | 7.8 | 0.2% | Apr 7, 2026 | mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-contro... |
| CVE-2026-34080 | MEDIUM | 5.5 | 0.2% | Apr 7, 2026 | xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassin... |
| CVE-2026-34045 | CRITICAL | 9.1 | 0.5% | Apr 7, 2026 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP... |
| CVE-2026-33439 | CRITICAL | 9.8 | 10.5% | Apr 7, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulner... |
| CVE-2026-32712 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to ... |
| CVE-2026-29181 | HIGH | 7.5 | 0.7% | Apr 7, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extractio... |
| CVE-2026-27949 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica... |
| CVE-2026-5741 | HIGH | 7.3 | 1.3% | Apr 7, 2026 | A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_con... |
| CVE-2026-5739 | HIGH | 7.3 | 0.4% | Apr 7, 2026 | A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.... |
| CVE-2026-3566 | — | — | — | Apr 7, 2026 | Rejected reason: After further discussion, the issue was determined to not meet the criteria for CVE assignment. |
| CVE-2026-39841 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi... |
| CVE-2026-39840 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati... |
| CVE-2026-39839 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi... |
| CVE-2026-39838 | MEDIUM | 6.9 | 0.4% | Apr 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati... |
| CVE-2026-39837 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Car... |
| CVE-2026-39395 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-... |
| CVE-2026-39382 | CRITICAL | 9.3 | 0.4% | Apr 7, 2026 | dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now