2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35515 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() int... |
| CVE-2026-35492 | MEDIUM | 6.5 | 0.4% | Apr 7, 2026 | Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vul... |
| CVE-2026-35491 | MEDIUM | 6.1 | 0.2% | Apr 7, 2026 | FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b... |
| CVE-2026-35487 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate... |
| CVE-2026-1079 | MEDIUM | 6 | 0.3% | Apr 7, 2026 | A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Auto... |
| CVE-2026-5384 | MEDIUM | 5.8 | 0.2% | Apr 7, 2026 | An issue that could allow a credential to be updated and used for a task from outside of the authorized organization sco... |
| CVE-2026-5383 | MEDIUM | 4.4 | 0.2% | Apr 7, 2026 | An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved.... |
| CVE-2026-5380 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields ... |
| CVE-2026-5378 | MEDIUM | 6.8 | 0.2% | Apr 7, 2026 | An issue that allowed administrators to create and update users outside of their authorized organization scope has been ... |
| CVE-2026-5376 | MEDIUM | 5.9 | 0.2% | Apr 7, 2026 | An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolve... |
| CVE-2026-5374 | MEDIUM | 5.8 | 0.2% | Apr 7, 2026 | An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization... |
| CVE-2026-5372 | MEDIUM | 6.4 | 0.2% | Apr 7, 2026 | An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This ... |
| CVE-2026-35484 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate... |
| CVE-2026-35483 | MEDIUM | 5.3 | 0.3% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate... |
| CVE-2026-35480 | MEDIUM | 6.2 | 0.2% | Apr 7, 2026 | go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ... |
| CVE-2026-35462 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are... |
| CVE-2026-35461 | MEDIUM | 4.3 | 0.2% | Apr 7, 2026 | Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows aut... |
| CVE-2026-35460 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Pa... |
| CVE-2026-33033 | MEDIUM | 6.5 | 0.7% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote a... |
| CVE-2026-3466 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkm... |
| CVE-2026-33866 | MEDIUM | 4.3 | 0.4% | Apr 7, 2026 | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due ... |
| CVE-2026-33865 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in it... |
| CVE-2026-4420 | MEDIUM | 5.4 | 0.2% | Apr 7, 2026 | Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its page creating functionality. An authenticated attacker ... |
| CVE-2026-34903 | MEDIUM | 5.4 | 0.3% | Apr 7, 2026 | Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-34899 | MEDIUM | 5.3 | 0.2% | Apr 7, 2026 | Missing Authorization vulnerability in Eniture technology LTL Freight Quotes – Worldwide Express Edition allows Exploiti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now