2026 CVE Vulnerabilities
50,941 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5704 | MEDIUM | 5.5 | 0.4% | Apr 6, 2026 | A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to ... |
| CVE-2026-5666 | MEDIUM | 5.5 | 0.3% | Apr 6, 2026 | A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit... |
| CVE-2026-34951 | MEDIUM | 6.1 | 0.1% | Apr 6, 2026 | Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Fo... |
| CVE-2026-34764 | MEDIUM | 5.5 | 0.1% | Apr 6, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph... |
| CVE-2026-34756 | MEDIUM | 6.5 | 0.4% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Servi... |
| CVE-2026-34755 | MEDIUM | 6.5 | 0.5% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.... |
| CVE-2026-34753 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side re... |
| CVE-2026-34589 | MEDIUM | 5 | 0.4% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34380 | MEDIUM | 5.9 | 0.3% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34378 | MEDIUM | 6.5 | 0.3% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-33727 | MEDIUM | 6.7 | 0.2% | Apr 6, 2026 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privil... |
| CVE-2026-33405 | MEDIUM | 4.8 | 0.2% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-31354 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 a... |
| CVE-2026-31353 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attac... |
| CVE-2026-31352 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allow... |
| CVE-2026-31351 | MEDIUM | 4.8 | 0.2% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo... |
| CVE-2026-31350 | MEDIUM | 5.4 | 0.2% | Apr 6, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitra... |
| CVE-2026-5661 | MEDIUM | 5.5 | 0.4% | Apr 6, 2026 | A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handle... |
| CVE-2026-34897 | MEDIUM | 6.5 | 0.2% | Apr 6, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi... |
| CVE-2026-33406 | MEDIUM | 6.1 | 0.3% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-33404 | MEDIUM | 6.1 | 0.1% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-33403 | MEDIUM | 6.1 | 0.2% | Apr 6, 2026 | Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic... |
| CVE-2026-32602 | MEDIUM | 4.2 | 0.1% | Apr 6, 2026 | Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnera... |
| CVE-2026-31153 | MEDIUM | 5.4 | 0.1% | Apr 6, 2026 | A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts o... |
| CVE-2026-31150 | MEDIUM | 4.3 | 0.2% | Apr 6, 2026 | Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now