2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41323 | CRITICAL | 9.1 | 0.6% | Apr 24, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc... |
| CVE-2026-33078 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a ... |
| CVE-2026-33076 | CRITICAL | 9.8 | 0.8% | Apr 24, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the hap... |
| CVE-2026-40630 | CRITICAL | 9.8 | 0.7% | Apr 24, 2026 | A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to certain configuration end... |
| CVE-2026-40620 | CRITICAL | 9.8 | 0.5% | Apr 24, 2026 | A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established wi... |
| CVE-2026-39462 | CRITICAL | 9.3 | 0.4% | Apr 24, 2026 | A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied ... |
| CVE-2026-35503 | CRITICAL | 9.8 | 0.5% | Apr 24, 2026 | A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on th... |
| CVE-2026-27843 | CRITICAL | 9.2 | 0.5% | Apr 24, 2026 | A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be... |
| CVE-2026-25775 | CRITICAL | 9.8 | 0.4% | Apr 24, 2026 | A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be per... |
| CVE-2026-41274 | CRITICAL | 9.8 | 0.5% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypher... |
| CVE-2026-35431 | CRITICAL | 10 | 0.5% | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perfo... |
| CVE-2026-33819 | CRITICAL | 9.8 | 0.8% | Apr 23, 2026 | Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. |
| CVE-2026-33102 | CRITICAL | 9.3 | 0.4% | Apr 23, 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege... |
| CVE-2026-26210 | CRITICAL | 9.8 | 0.7% | Apr 23, 2026 | KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the... |
| CVE-2026-26150 | CRITICAL | 10 | 0.6% | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-24303 | CRITICAL | 9.6 | 0.4% | Apr 23, 2026 | Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-41276 | CRITICAL | 9.8 | 6.9% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerabil... |
| CVE-2026-41268 | CRITICAL | 9.8 | 13.8% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vuln... |
| CVE-2026-41267 | CRITICAL | 9.8 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mas... |
| CVE-2026-41265 | CRITICAL | 9.8 | 0.5% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl... |
| CVE-2026-41264 | CRITICAL | 9.8 | 0.5% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl... |
| CVE-2026-25874 | CRITICAL | 9.8 | 15.5% | Apr 23, 2026 | LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.load... |
| CVE-2026-6074 | CRITICAL | 9.8 | 0.6% | Apr 23, 2026 | Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_fi... |
| CVE-2026-41247 | CRITICAL | 9.8 | 1.6% | Apr 23, 2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contai... |
| CVE-2026-6920 | CRITICAL | 9.6 | 0.2% | Apr 23, 2026 | Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now