2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41055MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks p...
CVE-2026-40935MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l...
CVE-2026-40929MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu...
CVE-2026-40928MEDIUM5.4WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/...
CVE-2026-40926HIGH7.1WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/cat...
CVE-2026-3307LOW2.7An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin acc...
CVE-2026-6832HIGH8.1Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authentic...
CVE-2026-6830MEDIUM4.8nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi...
CVE-2026-6829MEDIUM6.3nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or chan...
CVE-2026-6799MEDIUM6.3A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of ...
CVE-2026-41527MEDIUM6.9KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there i...
CVE-2026-40946CRITICAL9.2Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets...
CVE-2026-40945HIGH8.7Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token...
CVE-2026-40944MEDIUM6.9Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configurati...
CVE-2026-40943HIGH8.7Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing...
CVE-2026-40942MEDIUM6.3The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr...
CVE-2026-40939MEDIUM6.8The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr...
CVE-2026-40933CRITICAL9.9Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe s...
CVE-2026-40931HIGH7.8Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 rel...
CVE-2026-40706HIGH8.4In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that al...
CVE-2026-1354MEDIUM6.4Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bl...
CVE-2026-6823HIGH8.3HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote cha...
CVE-2026-6797MEDIUM5.3A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability is the function Zip...
CVE-2026-6796MEDIUM5.3A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file cor...
CVE-2026-40938HIGH8.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now