2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33813HIGH7.5Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
CVE-2026-33812MEDIUM6.1Parsing a malicious font file can cause excessive memory allocation.
CVE-2026-6745LOW3.5A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of th...
CVE-2026-6744MEDIUM6.3A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Hand...
CVE-2026-41456MEDIUM5.1Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that all...
CVE-2026-40868HIGH8.1Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall serv...
CVE-2026-40867HIGH7.1Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerabili...
CVE-2026-40866HIGH8.6Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference...
CVE-2026-40865HIGH7.1Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference...
CVE-2026-40614HIGH8.8PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer ov...
CVE-2026-40613HIGH7.5Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing fu...
CVE-2026-22751MEDIUM4.8Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTok...
CVE-2026-41194MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect act...
CVE-2026-41193CRITICAL9.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation ...
CVE-2026-41192HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust ...
CVE-2026-40611HIGH8.8Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in l...
CVE-2026-40608MEDIUM5.5Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the...
CVE-2026-40606MEDIUM4.8mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw...
CVE-2026-40604MEDIUM4.4ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the...
CVE-2026-40602MEDIUM5.6The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assi...
CVE-2026-40599HIGH7.1ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, Cle...
CVE-2026-40594MEDIUM4.8pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secu...
CVE-2026-40588HIGH8.1blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit...
CVE-2026-40587MEDIUM6.5blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profi...
CVE-2026-6743LOW3.5A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now