2026 CVE Vulnerabilities
66,707 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25833 | HIGH | 7.5 | 0.3% | Apr 1, 2026 | Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function |
| CVE-2026-5199 | LOW | 2.3 | 0.2% | Apr 1, 2026 | A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a vict... |
| CVE-2026-34875 | CRITICAL | 9.8 | 0.4% | Apr 1, 2026 | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key exp... |
| CVE-2026-34751 | CRITICAL | 9.1 | 0.3% | Apr 1, 2026 | Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and... |
| CVE-2026-34447 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ... |
| CVE-2026-34446 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ... |
| CVE-2026-34445 | HIGH | 8.6 | 0.3% | Apr 1, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ... |
| CVE-2026-34397 | HIGH | 7 | 0.2% | Apr 1, 2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3... |
| CVE-2026-34376 | HIGH | 7.5 | 0.4% | Apr 1, 2026 | PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to... |
| CVE-2026-34236 | CRITICAL | 9.8 | 0.2% | Apr 1, 2026 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in app... |
| CVE-2026-34222 | HIGH | 7.7 | 5.3% | Apr 1, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.... |
| CVE-2026-34159 | CRITICAL | 9.8 | 1.1% | Apr 1, 2026 | llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor()... |
| CVE-2026-34076 | HIGH | 7.4 | 0.3% | Apr 1, 2026 | Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to b... |
| CVE-2026-34072 | CRITICAL | 9.8 | 0.4% | Apr 1, 2026 | Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs... |
| CVE-2026-27489 | HIGH | 7.5 | 0.6% | Apr 1, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ... |
| CVE-2026-25834 | MEDIUM | 6.5 | 0.1% | Apr 1, 2026 | Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade. |
| CVE-2026-5310 | LOW | 2.5 | 0.1% | Apr 1, 2026 | A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the fil... |
| CVE-2026-34604 | HIGH | 8.8 | 0.4% | Apr 1, 2026 | Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containmen... |
| CVE-2026-34603 | HIGH | 8.3 | 0.4% | Apr 1, 2026 | Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal... |
| CVE-2026-33990 | CRITICAL | 9.1 | 0.3% | Apr 1, 2026 | Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, D... |
| CVE-2026-33978 | MEDIUM | 6.1 | 0.3% | Apr 1, 2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerabilit... |
| CVE-2026-33949 | HIGH | 8.1 | 0.4% | Apr 1, 2026 | Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql... |
| CVE-2026-30643 | CRITICAL | 9.8 | 0.6% | Apr 1, 2026 | An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module u... |
| CVE-2026-30273 | HIGH | 7.3 | 0.2% | Apr 1, 2026 | pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query ... |
| CVE-2026-2265 | MEDIUM | 6.5 | 0.4% | Apr 1, 2026 | An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now