2026 CVE Vulnerabilities
50,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5323 | MEDIUM | 5.3 | 0.1% | Apr 2, 2026 | A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the ... |
| CVE-2026-5321 | MEDIUM | 4.3 | 0.2% | Apr 2, 2026 | A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the compone... |
| CVE-2026-5319 | MEDIUM | 4.3 | 0.3% | Apr 2, 2026 | A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown f... |
| CVE-2026-5318 | MEDIUM | 4.3 | 0.6% | Apr 2, 2026 | A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/deco... |
| CVE-2026-1243 | MEDIUM | 5.4 | 0.2% | Apr 2, 2026 | IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authe... |
| CVE-2026-5316 | MEDIUM | 6.5 | 0.4% | Apr 2, 2026 | A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file s... |
| CVE-2026-32929 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 fi... |
| CVE-2026-32927 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Openi... |
| CVE-2026-32926 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a cra... |
| CVE-2026-5313 | MEDIUM | 4.3 | 0.3% | Apr 1, 2026 | A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the li... |
| CVE-2026-5312 | MEDIUM | 5.5 | 0.5% | Apr 1, 2026 | A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D... |
| CVE-2026-4820 | MEDIUM | 4.3 | 0.1% | Apr 1, 2026 | IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or sessi... |
| CVE-2026-4364 | MEDIUM | 5.4 | 0.1% | Apr 1, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-34530 | MEDIUM | 6.9 | 0.4% | Apr 1, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-34525 | MEDIUM | 5.3 | 0.3% | Apr 1, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host h... |
| CVE-2026-34519 | MEDIUM | 5.3 | 0.3% | Apr 1, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who... |
| CVE-2026-34518 | MEDIUM | 5.3 | 0.3% | Apr 1, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, when following ... |
| CVE-2026-34517 | MEDIUM | 5.3 | 0.4% | Apr 1, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, for some multip... |
| CVE-2026-34514 | MEDIUM | 5.3 | 0.3% | Apr 1, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who... |
| CVE-2026-2862 | MEDIUM | 5.3 | 0.4% | Apr 1, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-2475 | MEDIUM | 4.7 | 0.3% | Apr 1, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-1491 | MEDIUM | 5.3 | 0.4% | Apr 1, 2026 | IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ... |
| CVE-2026-5311 | MEDIUM | 5.5 | 1.0% | Apr 1, 2026 | A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-32... |
| CVE-2026-34750 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | Payload is a free and open source headless content management system. Prior to version 3.78.0 in @payloadcms/storage-azu... |
| CVE-2026-34749 | MEDIUM | 5.4 | 0.1% | Apr 1, 2026 | Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forg... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now