2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41135 | HIGH | 7.5 | 0.5% | Apr 22, 2026 | free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile c... |
| CVE-2026-41133 | HIGH | 8.8 | 0.3% | Apr 22, 2026 | pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `r... |
| CVE-2026-41131 | MEDIUM | 5 | 0.1% | Apr 22, 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode... |
| CVE-2026-41130 | MEDIUM | 5.5 | 0.3% | Apr 22, 2026 | Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through ... |
| CVE-2026-41129 | MEDIUM | 5.5 | 0.3% | Apr 22, 2026 | Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9... |
| CVE-2026-41128 | MEDIUM | 5.3 | 0.2% | Apr 22, 2026 | Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint... |
| CVE-2026-41127 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows vie... |
| CVE-2026-41126 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/... |
| CVE-2026-41064 | CRITICAL | 9.3 | 0.3% | Apr 22, 2026 | WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test... |
| CVE-2026-41059 | HIGH | 8.2 | 0.3% | Apr 22, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have ... |
| CVE-2026-40575 | CRITICAL | 9.1 | 0.5% | Apr 22, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may t... |
| CVE-2026-40343 | MEDIUM | 5.8 | 10.0% | Apr 22, 2026 | free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core... |
| CVE-2026-5921 | HIGH | 8.9 | 0.4% | Apr 21, 2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t... |
| CVE-2026-5845 | CRITICAL | 9.6 | 0.2% | Apr 21, 2026 | An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server ... |
| CVE-2026-5512 | MEDIUM | 4.3 | 0.3% | Apr 21, 2026 | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacke... |
| CVE-2026-4872 | — | — | — | Apr 21, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-4821 | — | — | — | Apr 21, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it was published in error. |
| CVE-2026-4296 | HIGH | 8.8 | 0.3% | Apr 21, 2026 | An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to byp... |
| CVE-2026-41063 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSa... |
| CVE-2026-41062 | MEDIUM | 6.5 | 0.7% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in comm... |
| CVE-2026-41061 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide... |
| CVE-2026-41060 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/fun... |
| CVE-2026-41058 | HIGH | 8.1 | 0.5% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `del... |
| CVE-2026-41057 | HIGH | 7.1 | 0.1% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e... |
| CVE-2026-41056 | HIGH | 8.1 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now