2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40050 | CRITICAL | 9.8 | 0.6% | Apr 21, 2026 | CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-4... |
| CVE-2026-38835 | CRITICAL | 9.8 | 2.1% | Apr 21, 2026 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount func... |
| CVE-2026-40498 | CRITICAL | 9.8 | 0.6% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ... |
| CVE-2026-6771 | CRITICAL | 9.8 | 0.3% | Apr 21, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thund... |
| CVE-2026-6768 | CRITICAL | 9.8 | 0.3% | Apr 21, 2026 | Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6760 | CRITICAL | 9.8 | 0.3% | Apr 21, 2026 | Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6748 | CRITICAL | 9.8 | 0.4% | Apr 21, 2026 | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR ... |
| CVE-2026-5965 | CRITICAL | 9.8 | 1.7% | Apr 21, 2026 | NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to in... |
| CVE-2026-40496 | CRITICAL | 9.1 | 0.4% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are g... |
| CVE-2026-39861 | CRITICAL | 10 | 0.5% | Apr 21, 2026 | Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processe... |
| CVE-2026-41329 | CRITICAL | 9.9 | 0.3% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbea... |
| CVE-2026-5450 | CRITICAL | 9.8 | 0.5% | Apr 20, 2026 | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version ... |
| CVE-2026-33432 | CRITICAL | 9.1 | 0.4% | Apr 20, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8... |
| CVE-2026-32613 | CRITICAL | 9.9 | 0.6% | Apr 20, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring ... |
| CVE-2026-32604 | CRITICAL | 9.9 | 0.6% | Apr 20, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2... |
| CVE-2026-29646 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to t... |
| CVE-2026-6257 | CRITICAL | 9.2 | 0.6% | Apr 20, 2026 | Vvveb CMS v1.0.8.2 contains a remote code execution vulnerability in its media management functionality where a missing ... |
| CVE-2026-32311 | CRITICAL | 9.8 | 0.5% | Apr 20, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-29649 | CRITICAL | 9.8 | 0.4% | Apr 20, 2026 | NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related f... |
| CVE-2026-39109 | CRITICAL | 9.4 | 0.3% | Apr 20, 2026 | SQL Injection vulnerability in Apartment Visitors Management System Apartment Visitors Management System V1.1 within the... |
| CVE-2026-30269 | CRITICAL | 9.9 | 0.3% | Apr 20, 2026 | Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a... |
| CVE-2026-39918 | CRITICAL | 9.8 | 0.7% | Apr 20, 2026 | Vvveb prior to 1.0.8.1 contains a code injection vulnerability in the installation endpoint where the subdir POST parame... |
| CVE-2026-24467 | CRITICAL | 9.8 | 0.9% | Apr 20, 2026 | OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa... |
| CVE-2026-5760 | CRITICAL | 9.8 | 0.9% | Apr 20, 2026 | SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious to... |
| CVE-2026-33557 | CRITICAL | 9.1 | 0.6% | Apr 20, 2026 | A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbeare... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now