2026 CVE Vulnerabilities
66,169 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35030 | CRITICAL | 9.4 | 0.5% | Apr 6, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authenti... |
| CVE-2026-35029 | HIGH | 8.8 | 26.4% | Apr 6, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/updat... |
| CVE-2026-34992 | HIGH | 7.5 | 0.1% | Apr 6, 2026 | Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encrypt... |
| CVE-2026-34989 | CRITICAL | 9 | 0.3% | Apr 6, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-34986 | HIGH | 7.5 | 0.7% | Apr 6, 2026 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup... |
| CVE-2026-34981 | MEDIUM | 5.8 | 0.3% | Apr 6, 2026 | The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url... |
| CVE-2026-34977 | CRITICAL | 9.8 | 0.8% | Apr 6, 2026 | Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user ... |
| CVE-2026-34976 | CRITICAL | 10 | 0.5% | Apr 6, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from... |
| CVE-2026-34975 | MEDIUM | 4.3 | 0.2% | Apr 6, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability wa... |
| CVE-2026-34841 | CRITICAL | 9.8 | 0.2% | Apr 6, 2026 | Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack ... |
| CVE-2026-34783 | HIGH | 8.1 | 0.5% | Apr 6, 2026 | Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferr... |
| CVE-2026-31313 | MEDIUM | 5.4 | 0.1% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo... |
| CVE-2026-5704 | MEDIUM | 5.5 | 0.4% | Apr 6, 2026 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to ... |
| CVE-2026-5666 | MEDIUM | 5.5 | 0.3% | Apr 6, 2026 | A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit... |
| CVE-2026-5665 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an ... |
| CVE-2026-34982 | HIGH | 8.2 | 0.5% | Apr 6, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbi... |
| CVE-2026-34969 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback f... |
| CVE-2026-34951 | MEDIUM | 6.1 | 0.1% | Apr 6, 2026 | Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Fo... |
| CVE-2026-34950 | CRITICAL | 9.1 | 0.2% | Apr 6, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-... |
| CVE-2026-34940 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/... |
| CVE-2026-34764 | MEDIUM | 5.5 | 0.1% | Apr 6, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph... |
| CVE-2026-34756 | MEDIUM | 6.5 | 0.4% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Servi... |
| CVE-2026-34755 | MEDIUM | 6.5 | 0.5% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.... |
| CVE-2026-34753 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side re... |
| CVE-2026-34589 | MEDIUM | 5 | 0.4% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now