2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-41304CRITICAL9.8WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the Clo...
CVE-2026-41144CRITICAL9.8F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedded software applicati...
CVE-2026-41064CRITICAL9.3WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test...
CVE-2026-40575CRITICAL9.1OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may t...
CVE-2026-5845CRITICAL9.6An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server ...
CVE-2026-40946CRITICAL9.2Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets...
CVE-2026-40933CRITICAL9.9Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe s...
CVE-2026-40911CRITICAL10WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays...
CVE-2026-40910CRITICAL9.1frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path...
CVE-2026-40892CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overf...
CVE-2026-34287CRITICAL9.1Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp...
CVE-2026-34286CRITICAL9.1Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp...
CVE-2026-34285CRITICAL9.1Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp...
CVE-2026-34279CRITICAL9.1Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana...
CVE-2026-34275CRITICAL9.8Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administ...
CVE-2026-33519CRITICAL9.8An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kube...
CVE-2026-40903CRITICAL9.1goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can ...
CVE-2026-40887CRITICAL9.1Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and ...
CVE-2026-40884CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the ...
CVE-2026-40872CRITICAL9.3mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin da...
CVE-2026-40372CRITICAL9.1Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges o...
CVE-2026-41193CRITICAL9.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation ...
CVE-2026-5652CRITICAL9An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authe...
CVE-2026-40576CRITICAL9.4excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists i...
CVE-2026-40569CRITICAL9FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerabi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now