2026 CVE Vulnerabilities
66,169 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35209 | HIGH | 7.5 | 0.4% | Apr 6, 2026 | defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pa... |
| CVE-2026-35177 | HIGH | 7.1 | 0.1% | Apr 6, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allo... |
| CVE-2026-35175 | MEDIUM | 6.5 | 0.3% | Apr 6, 2026 | Ajenti is a Linux and BSD modular server admin panel. Prior to 2.2.15, an authenticated user (using the auth_users plugi... |
| CVE-2026-35174 | HIGH | 7.2 | 0.6% | Apr 6, 2026 | Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the admin... |
| CVE-2026-35173 | MEDIUM | 6.5 | 0.2% | Apr 6, 2026 | Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post... |
| CVE-2026-35171 | CRITICAL | 9.8 | 0.7% | Apr 6, 2026 | Kedro is a toolbox for production-ready data science. Prior to 1.3.0, Kedro allows the logging configuration file path t... |
| CVE-2026-35167 | HIGH | 8.1 | 0.3% | Apr 6, 2026 | Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.... |
| CVE-2026-35166 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML re... |
| CVE-2026-35164 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload... |
| CVE-2026-35052 | CRITICAL | 9.8 | 0.6% | Apr 6, 2026 | D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3... |
| CVE-2026-35050 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save ... |
| CVE-2026-35047 | CRITICAL | 9.8 | 0.6% | Apr 6, 2026 | Brave CMS is an open-source CMS. Prior to 2.0.6, an Unrestricted File Upload vulnerability in the CKEditor endpoint allo... |
| CVE-2026-35046 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Tan... |
| CVE-2026-35045 | HIGH | 8.1 | 0.3% | Apr 6, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the... |
| CVE-2026-35044 | CRITICAL | 9.6 | 0.4% | Apr 6, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
| CVE-2026-35043 | HIGH | 7.8 | 0.3% | Apr 6, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
| CVE-2026-30613 | MEDIUM | 4.6 | 0.2% | Apr 6, 2026 | An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver... |
| CVE-2026-5670 | MEDIUM | 6.3 | 0.2% | Apr 6, 2026 | A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This is... |
| CVE-2026-5669 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th... |
| CVE-2026-5668 | LOW | 2.4 | 0.2% | Apr 6, 2026 | A flaw has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affect... |
| CVE-2026-35042 | HIGH | 7.5 | 0.2% | Apr 6, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (C... |
| CVE-2026-35039 | CRITICAL | 9.1 | 0.2% | Apr 6, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuil... |
| CVE-2026-35037 | HIGH | 7.2 | 0.3% | Apr 6, 2026 | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/... |
| CVE-2026-35036 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link ... |
| CVE-2026-35035 | CRITICAL | 9 | 0.5% | Apr 6, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now