2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41430MEDIUM6.1Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-...
CVE-2026-41324HIGH7.5basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded me...
CVE-2026-41323CRITICAL9.1Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc...
CVE-2026-41319MEDIUM5.9MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in ...
CVE-2026-41318MEDIUM5.4AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-41068HIGH7.7Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cros...
CVE-2026-2028MEDIUM5.3The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file owne...
CVE-2026-41317HIGH7.5Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-...
CVE-2026-41316HIGH8.1ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` ...
CVE-2026-41309HIGH8.2Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are ...
CVE-2026-41305MEDIUM6.1PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-40254MEDIUM6.1FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path...
CVE-2026-33318HIGH8.8Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) ...
CVE-2026-33317HIGH8.7OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-33208HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /co...
CVE-2026-33078CRITICAL9.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a ...
CVE-2026-33077HIGH7.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the old...
CVE-2026-33076CRITICAL9.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the hap...
CVE-2026-32952HIGH7.5go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NT...
CVE-2026-41325HIGH8.8Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor...
CVE-2026-40099MEDIUM6.5Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor...
CVE-2026-34587HIGH8.1Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control w...
CVE-2026-32870HIGH7.5Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>...
CVE-2026-31956MEDIUM4.3Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-31955MEDIUM4.9Xibo is an open source digital signage platform with a web content management system and Windows display player software...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now