2026 CVE Vulnerabilities

64,982 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4049——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-41455HIGH8.5WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL...
CVE-2026-41454HIGH8.7WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authe...
CVE-2026-41314MEDIUM6.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-41313MEDIUM6.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-41312MEDIUM6.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-41177MEDIUM5.5Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Sq...
CVE-2026-41175HIGH8.1Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulatin...
CVE-2026-41172HIGH7.3Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSR...
CVE-2026-41171HIGH7.3Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a...
CVE-2026-41170HIGH7.2Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `R...
CVE-2026-40517HIGH8.4radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows...
CVE-2026-41168MEDIUM5.3pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-41167CRITICAL9.1Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jell...
CVE-2026-41166HIGH7OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one K...
CVE-2026-41134HIGH7.8Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generat...
CVE-2026-40937HIGH8.3RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin...
CVE-2026-40882HIGH7.6OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses a...
CVE-2026-3837MEDIUM5.4An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution wh...
CVE-2026-34068MEDIUM6.8nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, ...
CVE-2026-34067MEDIUM6.5nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, ...
CVE-2026-33733HIGH7.2EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template manag...
CVE-2026-33656CRITICAL9.1EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formu...
CVE-2026-6019MEDIUM6.1http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It ...
CVE-2026-3673MEDIUM5.4An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim ope...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now