2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40252 | HIGH | 8.1 | 0.3% | Apr 10, 2026 | FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any... |
| CVE-2026-40242 | MEDIUM | 6.5 | 0.6% | Apr 10, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/template... |
| CVE-2026-40194 | LOW | 3.7 | 0.3% | Apr 10, 2026 | phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\N... |
| CVE-2026-40191 | MEDIUM | 6.8 | 0.1% | Apr 10, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta... |
| CVE-2026-40190 | CRITICAL | 9.8 | 0.2% | Apr 10, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScri... |
| CVE-2026-40189 | CRITICAL | 9.8 | 0.7% | Apr 10, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/ba... |
| CVE-2026-40188 | HIGH | 7.7 | 0.3% | Apr 10, 2026 | goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the... |
| CVE-2026-40185 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo m... |
| CVE-2026-40184 | MEDIUM | 5.3 | 0.2% | Apr 10, 2026 | TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. Th... |
| CVE-2026-40180 | HIGH | 7.5 | 0.4% | Apr 10, 2026 | Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.... |
| CVE-2026-40178 | MEDIUM | 5.9 | 0.2% | Apr 10, 2026 | ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a... |
| CVE-2026-40177 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a... |
| CVE-2026-40175 | MEDIUM | 4.8 | 1.9% | Apr 10, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a... |
| CVE-2026-40168 | HIGH | 8.2 | 0.4% | Apr 10, 2026 | Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Al... |
| CVE-2026-39922 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vuln... |
| CVE-2026-39921 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows a... |
| CVE-2026-32252 | HIGH | 7.7 | 0.3% | Apr 10, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-30232 | CRITICAL | 9.6 | 0.2% | Apr 10, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-3446 | MEDIUM | 6 | 0.2% | Apr 10, 2026 | When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded... |
| CVE-2026-33737 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string()... |
| CVE-2026-33736 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can en... |
| CVE-2026-33710 | HIGH | 7.5 | 0.3% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time... |
| CVE-2026-33708 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns... |
| CVE-2026-33707 | CRITICAL | 9.8 | 0.4% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism gener... |
| CVE-2026-33706 | HIGH | 7.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now