2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35451MEDIUM5.7Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote...
CVE-2026-30452MEDIUM6.5Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authen...
CVE-2026-29179LOW3.3October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission c...
CVE-2026-27937LOW3.1October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Script...
CVE-2026-26274MEDIUM6.6October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identifie...
CVE-2026-26067MEDIUM4.9October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information dis...
CVE-2026-25542MEDIUM6.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 an...
CVE-2026-24189HIGH8.2NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds re...
CVE-2026-24177HIGH7.7NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A succ...
CVE-2026-24176MEDIUM4.3NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespa...
CVE-2026-21571HIGH8.8This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11....
CVE-2026-40565MEDIUM6.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function i...
CVE-2026-40498CRITICAL9.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ...
CVE-2026-37748HIGH7.2Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php a...
CVE-2026-5789HIGH7.8Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execut...
CVE-2026-3298HIGH8.8The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the dat...
CVE-2026-31019HIGH8.8In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict...
CVE-2026-31018HIGH8.8In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not appl...
CVE-2026-31014MEDIUM6.3Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint p...
CVE-2026-31013MEDIUM6.1Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search paramet...
CVE-2026-29644MEDIUM5.3XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) h...
CVE-2026-1089MEDIUM6.5User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup,...
CVE-2026-0972MEDIUM5.4HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, det...
CVE-2026-0971MEDIUM4.3An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web User...
CVE-2026-6784HIGH7.5Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now