2026 CVE Vulnerabilities
66,324 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22664 | HIGH | 7.7 | 0.3% | Apr 3, 2026 | prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status pol... |
| CVE-2026-22663 | HIGH | 8.7 | 0.3% | Apr 3, 2026 | prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate che... |
| CVE-2026-22662 | MEDIUM | 5.3 | 0.2% | Apr 3, 2026 | prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media genera... |
| CVE-2026-22661 | HIGH | 8.6 | 0.4% | Apr 3, 2026 | prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attacker... |
| CVE-2026-5484 | MEDIUM | 5.5 | 0.3% | Apr 3, 2026 | A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the ... |
| CVE-2026-28798 | CRITICAL | 10 | 0.4% | Apr 3, 2026 | ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a... |
| CVE-2026-25726 | CRITICAL | 9.8 | 0.4% | Apr 3, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak ps... |
| CVE-2026-3184 | MEDIUM | 5.3 | 0.4% | Apr 3, 2026 | A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h`... |
| CVE-2026-2625 | MEDIUM | 5.5 | 0.1% | Apr 3, 2026 | A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Ha... |
| CVE-2026-5476 | MEDIUM | 4.6 | 0.2% | Apr 3, 2026 | A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize... |
| CVE-2026-5475 | MEDIUM | 5.5 | 0.2% | Apr 3, 2026 | A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_... |
| CVE-2026-32186 | CRITICAL | 9.8 | 0.7% | Apr 3, 2026 | Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a networ... |
| CVE-2026-0545 | CRITICAL | 9.8 | 4.4% | Apr 3, 2026 | In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authoriz... |
| CVE-2026-5474 | HIGH | 8.8 | 0.4% | Apr 3, 2026 | A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw... |
| CVE-2026-5473 | HIGH | 7 | 0.2% | Apr 3, 2026 | A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the componen... |
| CVE-2026-28373 | CRITICAL | 9.6 | 0.4% | Apr 3, 2026 | The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryp... |
| CVE-2026-5472 | MEDIUM | 6.3 | 0.2% | Apr 3, 2026 | A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Th... |
| CVE-2026-5471 | LOW | 3.3 | 0.1% | Apr 3, 2026 | A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function... |
| CVE-2026-5470 | MEDIUM | 6.3 | 0.2% | Apr 3, 2026 | A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca6... |
| CVE-2026-35218 | HIGH | 8.7 | 0.3% | Apr 3, 2026 | Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity... |
| CVE-2026-35216 | CRITICAL | 9 | 12.0% | Apr 3, 2026 | Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Co... |
| CVE-2026-35214 | HIGH | 8.7 | 0.6% | Apr 3, 2026 | Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin... |
| CVE-2026-31818 | CRITICAL | 9.9 | 0.4% | Apr 3, 2026 | Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerabilit... |
| CVE-2026-31404 | — | — | 0.1% | Apr 3, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-31403 | HIGH | 7.8 | 0.1% | Apr 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Hold net reference for the lifetime of /proc/... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now