2026 CVE Vulnerabilities
53,163 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35042 | HIGH | 7.5 | 0.2% | Apr 6, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (C... |
| CVE-2026-35037 | HIGH | 7.2 | 0.3% | Apr 6, 2026 | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/... |
| CVE-2026-35036 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link ... |
| CVE-2026-35029 | HIGH | 8.8 | 26.4% | Apr 6, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/updat... |
| CVE-2026-34992 | HIGH | 7.5 | 0.1% | Apr 6, 2026 | Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encrypt... |
| CVE-2026-34986 | HIGH | 7.5 | 0.7% | Apr 6, 2026 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup... |
| CVE-2026-34783 | HIGH | 8.1 | 0.5% | Apr 6, 2026 | Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferr... |
| CVE-2026-5665 | HIGH | 7.3 | 0.3% | Apr 6, 2026 | A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an ... |
| CVE-2026-34982 | HIGH | 8.2 | 0.5% | Apr 6, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbi... |
| CVE-2026-34969 | HIGH | 7.5 | 0.3% | Apr 6, 2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback f... |
| CVE-2026-34940 | HIGH | 8.8 | 0.4% | Apr 6, 2026 | KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/... |
| CVE-2026-34588 | HIGH | 7.8 | 0.5% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34379 | HIGH | 7.1 | 0.3% | Apr 6, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-34217 | HIGH | 7.2 | 0.3% | Apr 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sand... |
| CVE-2026-34211 | HIGH | 7.5 | 0.4% | Apr 6, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion... |
| CVE-2026-34148 | HIGH | 7.5 | 0.6% | Apr 6, 2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8,... |
| CVE-2026-33752 | HIGH | 8.6 | 0.5% | Apr 6, 2026 | curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges,... |
| CVE-2026-21382 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when handling power management requests with improperly sized input/output buffers. |
| CVE-2026-21381 | HIGH | 7.5 | 0.1% | Apr 6, 2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware... |
| CVE-2026-21380 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory. |
| CVE-2026-21378 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor... |
| CVE-2026-21376 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor... |
| CVE-2026-21375 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
| CVE-2026-21374 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio... |
| CVE-2026-21373 | HIGH | 7.8 | 0.1% | Apr 6, 2026 | Memory Corruption when accessing an output buffer without validating its size during IOCTL processing. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now