2026 CVE Vulnerabilities
65,722 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35457 | HIGH | 8.2 | 0.3% | Apr 7, 2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous... |
| CVE-2026-35405 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezv... |
| CVE-2026-33034 | HIGH | 7.5 | 0.8% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or u... |
| CVE-2026-33033 | MEDIUM | 6.5 | 0.7% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote a... |
| CVE-2026-30079 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration proced... |
| CVE-2026-24660 | HIGH | 8.1 | 0.6% | Apr 7, 2026 | A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A spec... |
| CVE-2026-24450 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An integer overflow vulnerability exists in the uncompressed_fp_dng_load_raw functionality of LibRaw Commit 8dc68e2. A s... |
| CVE-2026-21413 | CRITICAL | 9.8 | 0.7% | Apr 7, 2026 | A heap-based buffer overflow vulnerability exists in the lossless_jpeg_load_raw functionality of LibRaw Commit 0b56545 a... |
| CVE-2026-20911 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | A heap-based buffer overflow vulnerability exists in the HuffTable::initval functionality of LibRaw Commit 0b56545 and C... |
| CVE-2026-20889 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | A heap-based buffer overflow vulnerability exists in the x3f_thumb_loader functionality of LibRaw Commit d20315b. A spec... |
| CVE-2026-20884 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An integer overflow vulnerability exists in the deflate_dng_load_raw functionality of LibRaw Commit 8dc68e2. A specially... |
| CVE-2026-5627 | HIGH | 7.2 | 0.8% | Apr 7, 2026 | A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `Agen... |
| CVE-2026-35554 | HIGH | 8.7 | 0.3% | Apr 7, 2026 | A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently del... |
| CVE-2026-5735 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Memory safety bugs present in Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corr... |
| CVE-2026-5734 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Som... |
| CVE-2026-5733 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thu... |
| CVE-2026-5732 | HIGH | 8.8 | 0.4% | Apr 7, 2026 | Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox... |
| CVE-2026-5731 | CRITICAL | 9.8 | 0.3% | Apr 7, 2026 | Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Th... |
| CVE-2026-3466 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkm... |
| CVE-2026-33866 | MEDIUM | 4.3 | 0.4% | Apr 7, 2026 | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due ... |
| CVE-2026-33865 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in it... |
| CVE-2026-32144 | HIGH | 7.4 | 0.2% | Apr 7, 2026 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-respo... |
| CVE-2026-28808 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protect... |
| CVE-2026-23818 | CRITICAL | 9.6 | 0.3% | Apr 7, 2026 | A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Pre... |
| CVE-2026-22679 | CRITICAL | 9.8 | 21.5% | Apr 7, 2026 | Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now