2026 CVE Vulnerabilities
53,154 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34972 | HIGH | 8.8 | 0.2% | Apr 6, 2026 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2026-35203 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fie... |
| CVE-2026-35187 | HIGH | 7.7 | 0.3% | Apr 6, 2026 | pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API fu... |
| CVE-2026-35185 | HIGH | 7.5 | 0.4% | Apr 6, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is pub... |
| CVE-2026-35182 | HIGH | 8.8 | 0.3% | Apr 6, 2026 | Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update... |
| CVE-2026-35176 | HIGH | 7.1 | 0.2% | Apr 6, 2026 | openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exist... |
| CVE-2026-35172 | HIGH | 7.5 | 0.5% | Apr 6, 2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore ... |
| CVE-2026-35170 | HIGH | 7.1 | 0.2% | Apr 6, 2026 | openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exist... |
| CVE-2026-5678 | HIGH | 7.3 | 1.1% | Apr 6, 2026 | A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setSchedul... |
| CVE-2026-5677 | HIGH | 7.3 | 1.1% | Apr 6, 2026 | A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the... |
| CVE-2026-5676 | HIGH | 7.3 | 0.4% | Apr 6, 2026 | A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of ... |
| CVE-2026-5672 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown f... |
| CVE-2026-35470 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_... |
| CVE-2026-35209 | HIGH | 7.5 | 0.4% | Apr 6, 2026 | defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pa... |
| CVE-2026-35177 | HIGH | 7.1 | 0.1% | Apr 6, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allo... |
| CVE-2026-35174 | HIGH | 7.2 | 0.6% | Apr 6, 2026 | Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the admin... |
| CVE-2026-35167 | HIGH | 8.1 | 0.3% | Apr 6, 2026 | Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core.... |
| CVE-2026-35164 | HIGH | 8.8 | 0.7% | Apr 6, 2026 | Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload... |
| CVE-2026-35050 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save ... |
| CVE-2026-35045 | HIGH | 8.1 | 0.3% | Apr 6, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the... |
| CVE-2026-35043 | HIGH | 7.8 | 0.3% | Apr 6, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.... |
| CVE-2026-5669 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th... |
| CVE-2026-35042 | HIGH | 7.5 | 0.2% | Apr 6, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (C... |
| CVE-2026-35037 | HIGH | 7.2 | 0.3% | Apr 6, 2026 | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/... |
| CVE-2026-35036 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now