2026 CVE Vulnerabilities
53,154 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35489 | HIGH | 7.3 | 0.2% | Apr 7, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the... |
| CVE-2026-35488 | HIGH | 8.1 | 0.4% | Apr 7, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Rec... |
| CVE-2026-35486 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and... |
| CVE-2026-30460 | HIGH | 8.8 | 0.9% | Apr 7, 2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in t... |
| CVE-2026-1078 | HIGH | 7.2 | 0.3% | Apr 7, 2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R2... |
| CVE-2026-5373 | HIGH | 8.4 | 0.2% | Apr 7, 2026 | An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is... |
| CVE-2026-4740 | HIGH | 8.2 | 0.1% | Apr 7, 2026 | A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). ... |
| CVE-2026-3902 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote att... |
| CVE-2026-35485 | HIGH | 7.5 | 0.7% | Apr 7, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate... |
| CVE-2026-35464 | HIGH | 7.5 | 0.5% | Apr 7, 2026 | pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTI... |
| CVE-2026-35463 | HIGH | 8.8 | 0.8% | Apr 7, 2026 | pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTION... |
| CVE-2026-35457 | HIGH | 8.2 | 0.3% | Apr 7, 2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous... |
| CVE-2026-35405 | HIGH | 7.5 | 0.4% | Apr 7, 2026 | libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezv... |
| CVE-2026-33034 | HIGH | 7.5 | 0.8% | Apr 7, 2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or u... |
| CVE-2026-24660 | HIGH | 8.1 | 0.6% | Apr 7, 2026 | A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A spec... |
| CVE-2026-5627 | HIGH | 7.2 | 0.8% | Apr 7, 2026 | A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `Agen... |
| CVE-2026-35554 | HIGH | 8.7 | 0.3% | Apr 7, 2026 | A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently del... |
| CVE-2026-5733 | HIGH | 8.8 | 0.3% | Apr 7, 2026 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thu... |
| CVE-2026-5732 | HIGH | 8.8 | 0.4% | Apr 7, 2026 | Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox... |
| CVE-2026-32144 | HIGH | 7.4 | 0.2% | Apr 7, 2026 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-respo... |
| CVE-2026-22666 | HIGH | 8.6 | 15.5% | Apr 7, 2026 | Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_s... |
| CVE-2026-31842 | HIGH | 8.7 | 0.9% | Apr 7, 2026 | Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of t... |
| CVE-2026-34904 | HIGH | 7.5 | 0.1% | Apr 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request... |
| CVE-2026-34896 | HIGH | 7.5 | 0.1% | Apr 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows C... |
| CVE-2026-34197 | HIGH | 8.8 | 97.2% | Apr 7, 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now