2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31370MEDIUM6.3Honor E APP is affected by information leak vulnerability, successful exploitation of this vulnerability may affect serv...
CVE-2026-31369LOW3.2PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availab...
CVE-2026-31368HIGH7.8AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service avail...
CVE-2026-5965CRITICAL9.8NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to in...
CVE-2026-6675MEDIUM5.3The Responsive Blocks – Page Builder for Blocks & Patterns plugin for WordPress is vulnerable to Unauthenticated Open Em...
CVE-2026-6674MEDIUM6.5The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' parameter...
CVE-2026-40497HIGH8.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDanger...
CVE-2026-6058MEDIUM5.7** UNSUPPORTED WHEN ASSIGNED ** An improper encoding or escaping vulnerability in the CGI program of Zyxel WRE6505 v2 fi...
CVE-2026-40496CRITICAL9.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are g...
CVE-2026-40250HIGH7.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-40244HIGH7.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-39973HIGH7.1Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability...
CVE-2026-39886MEDIUM5.3OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-39866HIGH8.8Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command...
CVE-2026-40264LOW2.7OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation...
CVE-2026-39946MEDIUM4.9OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, when OpenBao revoked privile...
CVE-2026-39861CRITICAL10Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processe...
CVE-2026-39396MEDIUM6.5OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` i...
CVE-2026-39388LOW3.1OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, OpenBao's Certificate authen...
CVE-2026-39386HIGH8.8Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t...
CVE-2026-39378MEDIUM6.5The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versi...
CVE-2026-39377MEDIUM6.5The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions...
CVE-2026-39320HIGH7.5Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to...
CVE-2026-41331MEDIUM6.9OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that a...
CVE-2026-41330MEDIUM4.4OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to prop...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now