2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33813 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. |
| CVE-2026-33812 | MEDIUM | 6.1 | 0.1% | Apr 21, 2026 | Parsing a malicious font file can cause excessive memory allocation. |
| CVE-2026-6745 | LOW | 3.5 | 0.2% | Apr 21, 2026 | A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of th... |
| CVE-2026-6744 | MEDIUM | 6.3 | 0.2% | Apr 21, 2026 | A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Hand... |
| CVE-2026-41456 | MEDIUM | 5.1 | 0.4% | Apr 21, 2026 | Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that all... |
| CVE-2026-40868 | HIGH | 8.1 | 0.3% | Apr 21, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall serv... |
| CVE-2026-40867 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerabili... |
| CVE-2026-40866 | HIGH | 8.6 | 0.2% | Apr 21, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference... |
| CVE-2026-40865 | HIGH | 7.1 | 0.1% | Apr 21, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference... |
| CVE-2026-40614 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer ov... |
| CVE-2026-40613 | HIGH | 7.5 | 1.1% | Apr 21, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing fu... |
| CVE-2026-22751 | MEDIUM | 4.8 | 0.1% | Apr 21, 2026 | Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTok... |
| CVE-2026-41194 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect act... |
| CVE-2026-41193 | CRITICAL | 9.1 | 0.4% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation ... |
| CVE-2026-41192 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust ... |
| CVE-2026-40611 | HIGH | 8.8 | 0.3% | Apr 21, 2026 | Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in l... |
| CVE-2026-40608 | MEDIUM | 5.5 | 0.1% | Apr 21, 2026 | Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the... |
| CVE-2026-40606 | MEDIUM | 4.8 | 0.2% | Apr 21, 2026 | mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw... |
| CVE-2026-40604 | MEDIUM | 4.4 | 0.1% | Apr 21, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the... |
| CVE-2026-40602 | MEDIUM | 5.6 | 0.1% | Apr 21, 2026 | The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assi... |
| CVE-2026-40599 | HIGH | 7.1 | 0.1% | Apr 21, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, Cle... |
| CVE-2026-40594 | MEDIUM | 4.8 | 0.2% | Apr 21, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secu... |
| CVE-2026-40588 | HIGH | 8.1 | 0.2% | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit... |
| CVE-2026-40587 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profi... |
| CVE-2026-6743 | LOW | 3.5 | 0.2% | Apr 21, 2026 | A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now