2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41304 | CRITICAL | 9.8 | 2.2% | Apr 22, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the Clo... |
| CVE-2026-41144 | CRITICAL | 9.8 | 0.4% | Apr 22, 2026 | F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applicati... |
| CVE-2026-41064 | CRITICAL | 9.3 | 0.3% | Apr 22, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test... |
| CVE-2026-40575 | CRITICAL | 9.1 | 0.5% | Apr 22, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may t... |
| CVE-2026-5845 | CRITICAL | 9.6 | 0.2% | Apr 21, 2026 | An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server ... |
| CVE-2026-40946 | CRITICAL | 9.2 | 0.3% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets... |
| CVE-2026-40933 | CRITICAL | 9.9 | 2.0% | Apr 21, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe s... |
| CVE-2026-40911 | CRITICAL | 10 | 0.6% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays... |
| CVE-2026-40910 | CRITICAL | 9.1 | 0.3% | Apr 21, 2026 | frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path... |
| CVE-2026-40892 | CRITICAL | 9.8 | 0.4% | Apr 21, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overf... |
| CVE-2026-34287 | CRITICAL | 9.1 | 0.3% | Apr 21, 2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp... |
| CVE-2026-34286 | CRITICAL | 9.1 | 0.4% | Apr 21, 2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp... |
| CVE-2026-34285 | CRITICAL | 9.1 | 0.4% | Apr 21, 2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp... |
| CVE-2026-34279 | CRITICAL | 9.1 | 0.4% | Apr 21, 2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana... |
| CVE-2026-34275 | CRITICAL | 9.8 | 0.4% | Apr 21, 2026 | Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administ... |
| CVE-2026-33519 | CRITICAL | 9.8 | 0.3% | Apr 21, 2026 | An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kube... |
| CVE-2026-40903 | CRITICAL | 9.1 | 0.2% | Apr 21, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can ... |
| CVE-2026-40887 | CRITICAL | 9.1 | 1.8% | Apr 21, 2026 | Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and ... |
| CVE-2026-40884 | CRITICAL | 9.8 | 0.5% | Apr 21, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the ... |
| CVE-2026-40872 | CRITICAL | 9.3 | 0.3% | Apr 21, 2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin da... |
| CVE-2026-40372 | CRITICAL | 9.1 | 11.2% | Apr 21, 2026 | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges o... |
| CVE-2026-41193 | CRITICAL | 9.1 | 0.4% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation ... |
| CVE-2026-5652 | CRITICAL | 9 | 0.4% | Apr 21, 2026 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authe... |
| CVE-2026-40576 | CRITICAL | 9.4 | 0.4% | Apr 21, 2026 | excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists i... |
| CVE-2026-40569 | CRITICAL | 9 | 0.3% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerabi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now