2026 CVE Vulnerabilities
50,977 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34749 | MEDIUM | 5.4 | 0.1% | Apr 1, 2026 | Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forg... |
| CVE-2026-34871 | MEDIUM | 6.7 | 0.2% | Apr 1, 2026 | An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predict... |
| CVE-2026-34447 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ... |
| CVE-2026-34446 | MEDIUM | 5.5 | 0.2% | Apr 1, 2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ... |
| CVE-2026-25834 | MEDIUM | 6.5 | 0.1% | Apr 1, 2026 | Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade. |
| CVE-2026-33978 | MEDIUM | 6.1 | 0.3% | Apr 1, 2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerabilit... |
| CVE-2026-2265 | MEDIUM | 6.5 | 0.4% | Apr 1, 2026 | An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package... |
| CVE-2026-20174 | MEDIUM | 4.9 | 0.5% | Apr 1, 2026 | A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote at... |
| CVE-2026-20097 | MEDIUM | 6.5 | 0.5% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20096 | MEDIUM | 6.5 | 0.7% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20095 | MEDIUM | 6.5 | 0.9% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20090 | MEDIUM | 4.8 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20089 | MEDIUM | 4.8 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20088 | MEDIUM | 4.8 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20087 | MEDIUM | 4.8 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with ad... |
| CVE-2026-20085 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to co... |
| CVE-2026-20042 | MEDIUM | 6.5 | 0.3% | Apr 1, 2026 | A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encrypt... |
| CVE-2026-20041 | MEDIUM | 6.1 | 0.2% | Apr 1, 2026 | A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attac... |
| CVE-2026-5175 | MEDIUM | 5 | 0.3% | Apr 1, 2026 | Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenti... |
| CVE-2026-4989 | MEDIUM | 4.3 | 0.2% | Apr 1, 2026 | Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticate... |
| CVE-2026-4927 | MEDIUM | 6.5 | 0.2% | Apr 1, 2026 | Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privi... |
| CVE-2026-4925 | MEDIUM | 5 | 0.2% | Apr 1, 2026 | Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administra... |
| CVE-2026-4829 | MEDIUM | 5.4 | 0.2% | Apr 1, 2026 | Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an ... |
| CVE-2026-34510 | MEDIUM | 6.9 | 0.3% | Apr 1, 2026 | OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file... |
| CVE-2026-30526 | MEDIUM | 6.1 | 0.3% | Apr 1, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerabil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now