2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40927 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page,... |
| CVE-2026-40925 | HIGH | 8.3 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also r... |
| CVE-2026-40924 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-40923 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-40911 | CRITICAL | 10 | 0.6% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays... |
| CVE-2026-40910 | CRITICAL | 9.1 | 0.3% | Apr 21, 2026 | frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path... |
| CVE-2026-40906 | HIGH | 8.8 | 0.5% | Apr 21, 2026 | Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API... |
| CVE-2026-40905 | HIGH | 8.1 | 0.3% | Apr 21, 2026 | LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisoning vulnerability was ... |
| CVE-2026-40895 | HIGH | 7.5 | 0.5% | Apr 21, 2026 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows... |
| CVE-2026-40892 | CRITICAL | 9.8 | 0.4% | Apr 21, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overf... |
| CVE-2026-35252 | MEDIUM | 6.4 | 0.2% | Apr 21, 2026 | Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API). Support... |
| CVE-2026-35251 | HIGH | 7.5 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35250 | LOW | 2.3 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35249 | LOW | 3.2 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35248 | MEDIUM | 5 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35247 | MEDIUM | 6 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35246 | HIGH | 7.5 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35245 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35244 | MEDIUM | 5.2 | 0.2% | Apr 21, 2026 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme... |
| CVE-2026-35243 | HIGH | 7.8 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF ... |
| CVE-2026-35242 | HIGH | 7.5 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35241 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking... |
| CVE-2026-35240 | MEDIUM | 4.9 | 0.2% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2026-35239 | MEDIUM | 4.9 | 0.2% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affecte... |
| CVE-2026-35238 | MEDIUM | 4.9 | 0.2% | Apr 21, 2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now