2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33819 | CRITICAL | 9.8 | 0.8% | Apr 23, 2026 | Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. |
| CVE-2026-33102 | CRITICAL | 9.3 | 0.4% | Apr 23, 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege... |
| CVE-2026-32210 | HIGH | 7.5 | 0.6% | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofin... |
| CVE-2026-32172 | HIGH | 8 | 0.3% | Apr 23, 2026 | Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. |
| CVE-2026-2708 | MEDIUM | 5.3 | 0.3% | Apr 23, 2026 | A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_commo... |
| CVE-2026-26210 | CRITICAL | 9.8 | 0.7% | Apr 23, 2026 | KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the... |
| CVE-2026-26150 | CRITICAL | 10 | 0.6% | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-24303 | CRITICAL | 9.6 | 0.4% | Apr 23, 2026 | Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-6942 | HIGH | 8.8 | 1.9% | Apr 23, 2026 | radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to exe... |
| CVE-2026-6941 | HIGH | 7.8 | 0.2% | Apr 23, 2026 | radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to re... |
| CVE-2026-6940 | HIGH | 7.1 | 0.2% | Apr 23, 2026 | radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recurs... |
| CVE-2026-6376 | HIGH | 8.7 | 0.5% | Apr 23, 2026 | A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only ... |
| CVE-2026-6375 | HIGH | 8.7 | 0.3% | Apr 23, 2026 | A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without an... |
| CVE-2026-28525 | HIGH | 8.2 | 0.3% | Apr 23, 2026 | SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows ... |
| CVE-2026-41279 | HIGH | 7.5 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-spe... |
| CVE-2026-41278 | HIGH | 7.5 | 0.4% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1... |
| CVE-2026-41277 | HIGH | 8.8 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignme... |
| CVE-2026-41276 | CRITICAL | 9.8 | 6.9% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerabil... |
| CVE-2026-41275 | HIGH | 7.5 | 0.2% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password re... |
| CVE-2026-41273 | HIGH | 8.2 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contain... |
| CVE-2026-41272 | HIGH | 7.1 | 0.2% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core securi... |
| CVE-2026-41271 | HIGH | 8.3 | 0.2% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R... |
| CVE-2026-41270 | HIGH | 8.3 | 0.2% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R... |
| CVE-2026-41269 | HIGH | 8.8 | 0.5% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow co... |
| CVE-2026-41268 | CRITICAL | 9.8 | 13.8% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vuln... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now