2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41905HIGH7.7FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::san...
CVE-2026-41904HIGH7.6FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with...
CVE-2026-41903MEDIUM5.4FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user hold...
CVE-2026-41902CRITICAL9.1FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-s...
CVE-2026-41653HIGH7BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerabilit...
CVE-2026-8081MEDIUM6.3A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality...
CVE-2026-37709CRITICAL9.8Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958...
CVE-2026-7415CRITICAL9.8The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read ...
CVE-2026-7414CRITICAL9.8Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials ar...
CVE-2026-7413CRITICAL9.8A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen...
CVE-2026-7821CRITICAL9.1Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen...
CVE-2026-6973HIGH7.2An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic...
CVE-2026-5788CRITICAL9.8An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat...
CVE-2026-5787CRITICAL9.1An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut...
CVE-2026-5786HIGH8.8An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote...
CVE-2026-36388MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/...
CVE-2026-36387MEDIUM6.5A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This...
CVE-2026-36341MEDIUM5.4Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supp...
CVE-2026-44349HIGH7.1Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_finda...
CVE-2026-44264MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other...
CVE-2026-44263MEDIUM4.3Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe...
CVE-2026-42011HIGH7.4A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when p...
CVE-2026-41689MEDIUM6Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notifica...
CVE-2026-41688HIGH7.7Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF ...
CVE-2026-41687MEDIUM4.3Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in en...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now