2026 CVE Vulnerabilities
53,146 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28387 | HIGH | 8.1 | 0.8% | Apr 7, 2026 | Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with u... |
| CVE-2026-28386 | HIGH | 7.5 | 0.3% | Apr 7, 2026 | Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigg... |
| CVE-2026-35533 | HIGH | 7.8 | 0.2% | Apr 7, 2026 | mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-contro... |
| CVE-2026-29181 | HIGH | 7.5 | 0.7% | Apr 7, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extractio... |
| CVE-2026-5741 | HIGH | 7.3 | 1.3% | Apr 7, 2026 | A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_con... |
| CVE-2026-5739 | HIGH | 7.3 | 0.4% | Apr 7, 2026 | A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.... |
| CVE-2026-39376 | HIGH | 7.5 | 0.3% | Apr 7, 2026 | FastFeedParser is a high performance RSS, Atom and RDF parser. Prior to 0.5.10, when parse() fetches a URL that returns ... |
| CVE-2026-39374 | HIGH | 7.7 | 0.2% | Apr 7, 2026 | Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project mem... |
| CVE-2026-39371 | HIGH | 8.1 | 0.2% | Apr 7, 2026 | RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" fi... |
| CVE-2026-39370 | HIGH | 7.1 | 0.2% | Apr 7, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows at... |
| CVE-2026-39369 | HIGH | 7.6 | 0.4% | Apr 7, 2026 | WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php all... |
| CVE-2026-39364 | HIGH | 7.5 | 2.1% | Apr 7, 2026 | Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files... |
| CVE-2026-39363 | HIGH | 7.5 | 3.3% | Apr 7, 2026 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to ... |
| CVE-2026-39361 | HIGH | 7.7 | 0.3% | Apr 7, 2026 | OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src... |
| CVE-2026-39356 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identif... |
| CVE-2026-39322 | HIGH | 8.8 | 0.2% | Apr 7, 2026 | PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates... |
| CVE-2026-32864 | HIGH | 8.5 | 0.1% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW. ... |
| CVE-2026-32863 | HIGH | 8.5 | 0.2% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in... |
| CVE-2026-32862 | HIGH | 8.5 | 0.1% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabV... |
| CVE-2026-32861 | HIGH | 8.5 | 0.2% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI Lab... |
| CVE-2026-32860 | HIGH | 8.5 | 0.2% | Apr 7, 2026 | There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVI... |
| CVE-2026-5736 | HIGH | 7.3 | 0.3% | Apr 7, 2026 | A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-serve... |
| CVE-2026-39355 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnerability in the geneal... |
| CVE-2026-39344 | HIGH | 8.1 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, there is a Reflected Cross-Site Scripting (XSS) vu... |
| CVE-2026-39343 | HIGH | 7.2 | 0.3% | Apr 7, 2026 | ChurchCRM is an open-source church management system. Prior to 7.1.0, a SQL injection vulnerability exists in the EditEv... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now