2026 CVE Vulnerabilities
50,680 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35195 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco... |
| CVE-2026-34988 | MEDIUM | 6.3 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 28.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of it... |
| CVE-2026-34983 | MEDIUM | 5 | 0.1% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. In 43.0.0, cloning a wasmtime::Linker is unsound and can result in use-after-free... |
| CVE-2026-34945 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler conta... |
| CVE-2026-34944 | MEDIUM | 5.7 | 0.2% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, On x86-64 platforms with SSE3 disabl... |
| CVE-2026-34942 | MEDIUM | 6.5 | 0.4% | Apr 9, 2026 | Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transco... |
| CVE-2026-5329 | MEDIUM | 6.5 | 0.4% | Apr 9, 2026 | Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring... |
| CVE-2026-40071 | MEDIUM | 5.4 | 0.2% | Apr 9, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /j... |
| CVE-2026-39985 | MEDIUM | 6.1 | 0.2% | Apr 9, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-39961 | MEDIUM | 4.9 | 0.4% | Apr 9, 2026 | Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.3... |
| CVE-2026-39315 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documen... |
| CVE-2026-35207 | MEDIUM | 5.4 | 0.1% | Apr 9, 2026 | dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-contr... |
| CVE-2026-39957 | MEDIUM | 4.3 | 0.2% | Apr 9, 2026 | Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController:... |
| CVE-2026-39943 | MEDIUM | 6.5 | 0.2% | Apr 9, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revis... |
| CVE-2026-39856 | MEDIUM | 5.5 | 0.1% | Apr 9, 2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulne... |
| CVE-2026-39855 | MEDIUM | 5.5 | 0.1% | Apr 9, 2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulner... |
| CVE-2026-5960 | MEDIUM | 4.3 | 0.3% | Apr 9, 2026 | A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of th... |
| CVE-2026-39941 | MEDIUM | 6.1 | 0.3% | Apr 9, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied inpu... |
| CVE-2026-35041 | MEDIUM | 6.5 | 0.3% | Apr 9, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in... |
| CVE-2026-35040 | MEDIUM | 5.3 | 0.4% | Apr 9, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in... |
| CVE-2026-33005 | MEDIUM | 4.3 | 0.4% | Apr 9, 2026 | Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web se... |
| CVE-2026-4114 | MEDIUM | 6.6 | 0.6% | Apr 9, 2026 | Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin ... |
| CVE-2026-34757 | MEDIUM | 4.4 | 0.2% | Apr 9, 2026 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2026-3005 | MEDIUM | 6.4 | 0.3% | Apr 9, 2026 | The List category posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catlist' sho... |
| CVE-2026-2519 | MEDIUM | 5.3 | 0.5% | Apr 9, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to price manipulation v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now