2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5652 | CRITICAL | 9 | 0.4% | Apr 21, 2026 | An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authe... |
| CVE-2026-41191 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave... |
| CVE-2026-41190 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CON... |
| CVE-2026-41189 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is autho... |
| CVE-2026-41183 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is... |
| CVE-2026-40592 | MEDIUM | 5.9 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conver... |
| CVE-2026-40591 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation ... |
| CVE-2026-40590 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal expose... |
| CVE-2026-40589 | HIGH | 7.6 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit ... |
| CVE-2026-40586 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of... |
| CVE-2026-40585 | HIGH | 7.4 | 0.2% | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-charac... |
| CVE-2026-40584 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the ... |
| CVE-2026-40583 | HIGH | 8.2 | 0.4% | Apr 21, 2026 | UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vo... |
| CVE-2026-40576 | CRITICAL | 9.4 | 0.4% | Apr 21, 2026 | excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists i... |
| CVE-2026-40574 | MEDIUM | 6.8 | 0.2% | Apr 21, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization b... |
| CVE-2026-40570 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action ... |
| CVE-2026-40569 | CRITICAL | 9 | 0.3% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerabi... |
| CVE-2026-40568 | HIGH | 8.5 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripti... |
| CVE-2026-40567 | MEDIUM | 5.8 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ... |
| CVE-2026-40566 | MEDIUM | 4.1 | 0.3% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forge... |
| CVE-2026-40279 | LOW | 3.7 | 0.2% | Apr 21, 2026 | BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in... |
| CVE-2026-40161 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-40050 | CRITICAL | 9.8 | 0.6% | Apr 21, 2026 | CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-4... |
| CVE-2026-38835 | CRITICAL | 9.8 | 2.1% | Apr 21, 2026 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount func... |
| CVE-2026-38834 | HIGH | 7.3 | 1.3% | Apr 21, 2026 | Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now