2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41135HIGH7.5free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile c...
CVE-2026-41133HIGH8.8pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `r...
CVE-2026-41131MEDIUM5OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode...
CVE-2026-41130MEDIUM5.5Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through ...
CVE-2026-41129MEDIUM5.5Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9...
CVE-2026-41128MEDIUM5.3Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint...
CVE-2026-41127MEDIUM6.5BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows vie...
CVE-2026-41126MEDIUM4.3BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/...
CVE-2026-41064CRITICAL9.3WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test...
CVE-2026-41059HIGH8.2OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have ...
CVE-2026-40575CRITICAL9.1OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may t...
CVE-2026-40343MEDIUM5.8free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core...
CVE-2026-5921HIGH8.9A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t...
CVE-2026-5845CRITICAL9.6An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server ...
CVE-2026-5512MEDIUM4.3An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacke...
CVE-2026-4872——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-4821——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it was published in error.
CVE-2026-4296HIGH8.8An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to byp...
CVE-2026-41063MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSa...
CVE-2026-41062MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in comm...
CVE-2026-41061MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide...
CVE-2026-41060MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/fun...
CVE-2026-41058HIGH8.1WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `del...
CVE-2026-41057HIGH7.1WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e...
CVE-2026-41056HIGH8.1WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now