2026 CVE Vulnerabilities
65,722 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5382 | LOW | 3 | 0.2% | Apr 7, 2026 | An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resol... |
| CVE-2026-5381 | LOW | 2.2 | 0.2% | Apr 7, 2026 | An issue that could expose task information outside of the authorized organization scope has been resolved. This is an i... |
| CVE-2026-5380 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields ... |
| CVE-2026-5379 | LOW | 3 | 0.1% | Apr 7, 2026 | An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope h... |
| CVE-2026-5378 | MEDIUM | 6.8 | 0.2% | Apr 7, 2026 | An issue that allowed administrators to create and update users outside of their authorized organization scope has been ... |
| CVE-2026-5376 | MEDIUM | 5.9 | 0.2% | Apr 7, 2026 | An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolve... |
| CVE-2026-5375 | LOW | 2.7 | 0.2% | Apr 7, 2026 | An issue that could allow a user with access to a credential to view sensitive fields through an API response has been r... |
| CVE-2026-5374 | MEDIUM | 5.8 | 0.2% | Apr 7, 2026 | An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization... |
| CVE-2026-5373 | HIGH | 8.4 | 0.2% | Apr 7, 2026 | An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is... |
| CVE-2026-5372 | MEDIUM | 6.4 | 0.2% | Apr 7, 2026 | An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This ... |
| CVE-2026-4740 | HIGH | 8.2 | 0.1% | Apr 7, 2026 | A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). ... |
| CVE-2026-4292 | LOW | 2.7 | 0.3% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `Mod... |
| CVE-2026-4277 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model i... |
| CVE-2026-3902 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote att... |
| CVE-2026-35485 | HIGH | 7.5 | 0.7% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate... |
| CVE-2026-35484 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate... |
| CVE-2026-35483 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate... |
| CVE-2026-35481 | — | — | — | Apr 7, 2026 | Rejected reason: Further research determined the issue does not satisfy the assignment rules. |
| CVE-2026-35480 | MEDIUM | 6.2 | 0.2% | Apr 7, 2026 | go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ... |
| CVE-2026-35464 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTI... |
| CVE-2026-35463 | HIGH | 8.8 | 0.8% | Apr 7, 2026 | pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTION... |
| CVE-2026-35462 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are... |
| CVE-2026-35461 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows aut... |
| CVE-2026-35460 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Pa... |
| CVE-2026-35458 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now