2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41320MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a special...
CVE-2026-40909MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) c...
CVE-2026-40908MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root execut...
CVE-2026-40907MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/...
CVE-2026-40903CRITICAL9.1goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can ...
CVE-2026-40890HIGH7.5The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing...
CVE-2026-40889MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authentica...
CVE-2026-40888MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authent...
CVE-2026-40887CRITICAL9.1Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and ...
CVE-2026-40885HIGH8.8goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials thr...
CVE-2026-40884CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP authentication bypass when the ...
CVE-2026-40883HIGH8.1goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forger...
CVE-2026-40881HIGH7.5ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when dese...
CVE-2026-40880HIGH8.1ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic...
CVE-2026-40879HIGH7.5Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends man...
CVE-2026-40878LOW2.1mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow ...
CVE-2026-40876HIGH8.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-ba...
CVE-2026-40875HIGH7mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user das...
CVE-2026-40874MEDIUM6mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administr...
CVE-2026-40873HIGH8.9mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quaranti...
CVE-2026-40872CRITICAL9.3mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin da...
CVE-2026-40871HIGH7.2mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-or...
CVE-2026-40870HIGH7.5Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the r...
CVE-2026-40869MEDIUM6.5Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vu...
CVE-2026-40372CRITICAL9.1Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now