2026 CVE Vulnerabilities
66,201 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34950 | CRITICAL | 9.1 | 0.2% | Apr 6, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-... |
| CVE-2026-34940 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/... |
| CVE-2026-34764 | MEDIUM | 5.5 | 0.1% | Apr 6, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph... |
| CVE-2026-34756 | MEDIUM | 6.5 | 0.4% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Servi... |
| CVE-2026-34755 | MEDIUM | 6.5 | 0.5% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.... |
| CVE-2026-34753 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side re... |
| CVE-2026-34589 | MEDIUM | 5 | 0.4% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34588 | HIGH | 7.8 | 0.5% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34444 | CRITICAL | 10 | 0.6% | Apr 6, 2026 | Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently ap... |
| CVE-2026-34402 | — | — | — | Apr 6, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39330. Reason: This candidate is a ... |
| CVE-2026-34380 | MEDIUM | 5.9 | 0.3% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34379 | HIGH | 7.1 | 0.3% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34378 | MEDIUM | 6.5 | 0.3% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34217 | HIGH | 7.2 | 0.3% | Apr 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sand... |
| CVE-2026-34211 | HIGH | 7.5 | 0.4% | Apr 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion... |
| CVE-2026-34208 | CRITICAL | 10 | 0.6% | Apr 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for... |
| CVE-2026-34148 | HIGH | 7.5 | 0.6% | Apr 6, 2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8,... |
| CVE-2026-33752 | HIGH | 8.6 | 0.5% | Apr 6, 2026 | curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges,... |
| CVE-2026-33727 | MEDIUM | 6.7 | 0.2% | Apr 6, 2026 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privil... |
| CVE-2026-33405 | MEDIUM | 4.8 | 0.2% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-31354 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 a... |
| CVE-2026-31353 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attac... |
| CVE-2026-31352 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allow... |
| CVE-2026-31351 | MEDIUM | 4.8 | 0.2% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo... |
| CVE-2026-31350 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitra... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now