2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35446 | HIGH | 8.6 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-35401 | HIGH | 7.5 | 0.3% | Apr 8, 2026 | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can i... |
| CVE-2026-34724 | HIGH | 7.2 | 0.3% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vul... |
| CVE-2026-34723 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote att... |
| CVE-2026-34392 | HIGH | 7.5 | 0.3% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-33350 | HIGH | 7.5 | 0.2% | Apr 8, 2026 | LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project... |
| CVE-2026-30818 | HIGH | 8 | 1.2% | Apr 8, 2026 | An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent... |
| CVE-2026-30815 | HIGH | 8 | 1.2% | Apr 8, 2026 | An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent... |
| CVE-2026-30814 | HIGH | 8 | 0.4% | Apr 8, 2026 | A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attac... |
| CVE-2026-27806 | HIGH | 7.8 | 0.1% | Apr 8, 2026 | Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotati... |
| CVE-2026-33756 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query b... |
| CVE-2026-33458 | HIGH | 7.7 | 0.2% | Apr 8, 2026 | Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user w... |
| CVE-2026-32590 | HIGH | 8.8 | 0.4% | Apr 8, 2026 | A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores interm... |
| CVE-2026-32589 | HIGH | 7.4 | 0.2% | Apr 8, 2026 | A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any reposit... |
| CVE-2026-4837 | HIGH | 7.2 | 0.4% | Apr 8, 2026 | An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically all... |
| CVE-2026-4498 | HIGH | 7.7 | 0.3% | Apr 8, 2026 | Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index dat... |
| CVE-2026-30080 | HIGH | 7.5 | 0.3% | Apr 8, 2026 | OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported int... |
| CVE-2026-30075 | HIGH | 7.5 | 0.4% | Apr 8, 2026 | OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentic... |
| CVE-2026-33753 | HIGH | 7.5 | 0.2% | Apr 8, 2026 | rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an ... |
| CVE-2026-39408 | HIGH | 7.5 | 0.5% | Apr 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal... |
| CVE-2026-39393 | HIGH | 8.1 | 0.4% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-39389 | HIGH | 7.2 | 0.5% | Apr 8, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-5795 | HIGH | 7.4 | 0.5% | Apr 8, 2026 | In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. ... |
| CVE-2026-5302 | HIGH | 8.1 | 0.3% | Apr 8, 2026 | CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and se... |
| CVE-2026-27102 | HIGH | 7.8 | 0.1% | Apr 8, 2026 | Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect p... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now