2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35451 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote... |
| CVE-2026-30452 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authen... |
| CVE-2026-29179 | LOW | 3.3 | 0.1% | Apr 21, 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, fine-grained sub-permission c... |
| CVE-2026-27937 | LOW | 3.1 | 0.1% | Apr 21, 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.16 and 4.1.16, a reflected Cross-Site Script... |
| CVE-2026-26274 | MEDIUM | 6.6 | 0.2% | Apr 21, 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identifie... |
| CVE-2026-26067 | MEDIUM | 4.9 | 0.2% | Apr 21, 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information dis... |
| CVE-2026-25542 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 an... |
| CVE-2026-24189 | HIGH | 8.2 | 0.3% | Apr 21, 2026 | NVIDIA CUDA-Q contains a vulnerability in an endpoint, where an unauthenticated attacker could cause an out-of-bounds re... |
| CVE-2026-24177 | HIGH | 7.7 | 0.2% | Apr 21, 2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A succ... |
| CVE-2026-24176 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespa... |
| CVE-2026-21571 | HIGH | 8.8 | 1.3% | Apr 21, 2026 | This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.... |
| CVE-2026-40565 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function i... |
| CVE-2026-40498 | CRITICAL | 9.8 | 0.6% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ... |
| CVE-2026-37748 | HIGH | 7.2 | 0.8% | Apr 21, 2026 | Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php a... |
| CVE-2026-5789 | HIGH | 7.8 | 0.1% | Apr 21, 2026 | Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execut... |
| CVE-2026-3298 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the dat... |
| CVE-2026-31019 | HIGH | 8.8 | 0.6% | Apr 21, 2026 | In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict... |
| CVE-2026-31018 | HIGH | 8.8 | 0.3% | Apr 21, 2026 | In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not appl... |
| CVE-2026-31014 | MEDIUM | 6.3 | 0.1% | Apr 21, 2026 | Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint p... |
| CVE-2026-31013 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search paramet... |
| CVE-2026-29644 | MEDIUM | 5.3 | 0.1% | Apr 21, 2026 | XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) h... |
| CVE-2026-1089 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup,... |
| CVE-2026-0972 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, det... |
| CVE-2026-0971 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web User... |
| CVE-2026-6784 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now