2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41055 | MEDIUM | 5.3 | 0.4% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks p... |
| CVE-2026-40935 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l... |
| CVE-2026-40929 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu... |
| CVE-2026-40928 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/... |
| CVE-2026-40926 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/cat... |
| CVE-2026-3307 | LOW | 2.7 | 0.3% | Apr 21, 2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin acc... |
| CVE-2026-6832 | HIGH | 8.1 | 0.5% | Apr 21, 2026 | Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authentic... |
| CVE-2026-6830 | MEDIUM | 4.8 | 0.1% | Apr 21, 2026 | nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi... |
| CVE-2026-6829 | MEDIUM | 6.3 | 0.3% | Apr 21, 2026 | nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or chan... |
| CVE-2026-6799 | MEDIUM | 6.3 | 1.2% | Apr 21, 2026 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of ... |
| CVE-2026-41527 | MEDIUM | 6.9 | 0.1% | Apr 21, 2026 | KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there i... |
| CVE-2026-40946 | CRITICAL | 9.2 | 0.3% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets... |
| CVE-2026-40945 | HIGH | 8.7 | 0.3% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token... |
| CVE-2026-40944 | MEDIUM | 6.9 | 0.2% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configurati... |
| CVE-2026-40943 | HIGH | 8.7 | 0.2% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing... |
| CVE-2026-40942 | MEDIUM | 6.3 | 0.3% | Apr 21, 2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr... |
| CVE-2026-40939 | MEDIUM | 6.8 | 0.2% | Apr 21, 2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr... |
| CVE-2026-40933 | CRITICAL | 9.9 | 2.0% | Apr 21, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe s... |
| CVE-2026-40931 | HIGH | 7.8 | 0.2% | Apr 21, 2026 | Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 rel... |
| CVE-2026-40706 | HIGH | 8.4 | 0.2% | Apr 21, 2026 | In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that al... |
| CVE-2026-1354 | MEDIUM | 6.4 | 0.1% | Apr 21, 2026 | Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bl... |
| CVE-2026-6823 | HIGH | 8.3 | 0.3% | Apr 21, 2026 | HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote cha... |
| CVE-2026-6797 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability is the function Zip... |
| CVE-2026-6796 | MEDIUM | 5.3 | 0.1% | Apr 21, 2026 | A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file cor... |
| CVE-2026-40938 | HIGH | 8.5 | 0.8% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now