2026 CVE Vulnerabilities
65,717 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35520 | HIGH | 8.8 | 0.7% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35519 | HIGH | 8.8 | 0.5% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35518 | HIGH | 8.8 | 0.7% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35517 | HIGH | 8.8 | 0.9% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35516 | MEDIUM | 5 | 0.3% | Apr 7, 2026 | LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand:... |
| CVE-2026-35515 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() int... |
| CVE-2026-35492 | MEDIUM | 6.5 | 0.4% | Apr 7, 2026 | Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vul... |
| CVE-2026-35491 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35490 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required... |
| CVE-2026-35489 | HIGH | 7.3 | 0.2% | Apr 7, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the... |
| CVE-2026-35488 | HIGH | 8.1 | 0.4% | Apr 7, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Rec... |
| CVE-2026-35487 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate... |
| CVE-2026-35486 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and... |
| CVE-2026-33816 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | Memory-safety vulnerability in github.com/jackc/pgx/v5. |
| CVE-2026-33815 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | Memory-safety vulnerability in github.com/jackc/pgx/v5. |
| CVE-2026-30460 | HIGH | 8.8 | 0.9% | Apr 7, 2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in t... |
| CVE-2026-1079 | MEDIUM | 6 | 0.3% | Apr 7, 2026 | A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Auto... |
| CVE-2026-1078 | HIGH | 7.2 | 0.3% | Apr 7, 2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R2... |
| CVE-2026-5384 | MEDIUM | 5.8 | 0.2% | Apr 7, 2026 | An issue that could allow a credential to be updated and used for a task from outside of the authorized organization sco... |
| CVE-2026-5383 | MEDIUM | 4.4 | 0.2% | Apr 7, 2026 | An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved.... |
| CVE-2026-5382 | LOW | 3 | 0.2% | Apr 7, 2026 | An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resol... |
| CVE-2026-5381 | LOW | 2.2 | 0.2% | Apr 7, 2026 | An issue that could expose task information outside of the authorized organization scope has been resolved. This is an i... |
| CVE-2026-5380 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields ... |
| CVE-2026-5379 | LOW | 3 | 0.1% | Apr 7, 2026 | An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope h... |
| CVE-2026-5378 | MEDIUM | 6.8 | 0.2% | Apr 7, 2026 | An issue that allowed administrators to create and update users outside of their authorized organization scope has been ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now