2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39981 | HIGH | 8.8 | 1.3% | Apr 9, 2026 | AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities ext... |
| CVE-2026-39980 | HIGH | 7.2 | 0.5% | Apr 9, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the... |
| CVE-2026-39911 | HIGH | 8.8 | 0.5% | Apr 9, 2026 | Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerab... |
| CVE-2026-30478 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalat... |
| CVE-2026-1584 | HIGH | 7.5 | 1.3% | Apr 9, 2026 | A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially cra... |
| CVE-2026-5961 | HIGH | 7.3 | 0.3% | Apr 9, 2026 | A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects u... |
| CVE-2026-40046 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for... |
| CVE-2026-39976 | HIGH | 7.1 | 0.3% | Apr 9, 2026 | Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Byp... |
| CVE-2026-39974 | HIGH | 8.5 | 0.3% | Apr 9, 2026 | n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node docum... |
| CVE-2026-39972 | HIGH | 7.1 | 0.3% | Apr 9, 2026 | Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior ... |
| CVE-2026-39959 | HIGH | 7.1 | 0.1% | Apr 9, 2026 | Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to m... |
| CVE-2026-39942 | HIGH | 8.8 | 0.2% | Apr 9, 2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id}... |
| CVE-2026-4878 | HIGH | 7 | 0.2% | Apr 9, 2026 | A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition... |
| CVE-2026-39853 | HIGH | 7.8 | 0.2% | Apr 9, 2026 | osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vul... |
| CVE-2026-39843 | HIGH | 7.7 | 0.2% | Apr 9, 2026 | Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw ... |
| CVE-2026-35205 | HIGH | 7.8 | 0.2% | Apr 9, 2026 | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (... |
| CVE-2026-35204 | HIGH | 8.6 | 0.2% | Apr 9, 2026 | Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installe... |
| CVE-2026-34020 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint us... |
| CVE-2026-33266 | HIGH | 7.5 | 0.2% | Apr 9, 2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set ... |
| CVE-2026-5959 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is ... |
| CVE-2026-5444 | HIGH | 7.1 | 0.2% | Apr 9, 2026 | A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image e... |
| CVE-2026-5441 | HIGH | 7.1 | 0.1% | Apr 9, 2026 | An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1... |
| CVE-2026-5440 | HIGH | 7.5 | 0.6% | Apr 9, 2026 | A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The se... |
| CVE-2026-5439 | HIGH | 7.5 | 0.4% | Apr 9, 2026 | A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded... |
| CVE-2026-5438 | HIGH | 7.5 | 0.5% | Apr 9, 2026 | A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The se... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now