2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5652CRITICAL9An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authe...
CVE-2026-41191HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave...
CVE-2026-41190HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CON...
CVE-2026-41189HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is autho...
CVE-2026-41183MEDIUM4.3FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is...
CVE-2026-40592MEDIUM5.9FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conver...
CVE-2026-40591HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation ...
CVE-2026-40590MEDIUM4.3FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal expose...
CVE-2026-40589HIGH7.6FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit ...
CVE-2026-40586HIGH7.5blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of...
CVE-2026-40585HIGH7.4blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-charac...
CVE-2026-40584HIGH7.5RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the ...
CVE-2026-40583HIGH8.2UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vo...
CVE-2026-40576CRITICAL9.4excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists i...
CVE-2026-40574MEDIUM6.8OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization b...
CVE-2026-40570MEDIUM5.7FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action ...
CVE-2026-40569CRITICAL9FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerabi...
CVE-2026-40568HIGH8.5FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripti...
CVE-2026-40567MEDIUM5.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ...
CVE-2026-40566MEDIUM4.1FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forge...
CVE-2026-40279LOW3.7BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in...
CVE-2026-40161MEDIUM6.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...
CVE-2026-40050CRITICAL9.8CrowdStrike has released security updates to address a critical unauthenticated path traversal vulnerability (CVE-2026-4...
CVE-2026-38835CRITICAL9.8Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount func...
CVE-2026-38834HIGH7.3Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the do_ping_action function via th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now