2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6610 | LOW | 3.7 | 0.3% | Apr 20, 2026 | A vulnerability has been found in liangliangyy DjangoBlog up to 2.1.0.0. The impacted element is an unknown function of ... |
| CVE-2026-6600 | LOW | 3.5 | 0.2% | Apr 20, 2026 | A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src... |
| CVE-2026-6597 | LOW | 2.7 | 0.3% | Apr 20, 2026 | A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_ter... |
| CVE-2026-6593 | LOW | 3.5 | 0.2% | Apr 20, 2026 | A vulnerability was found in ComfyUI up to 0.13.0. Affected by this issue is some unknown functionality of the file serv... |
| CVE-2026-6592 | LOW | 3.5 | 0.3% | Apr 20, 2026 | A vulnerability has been found in ComfyUI up to 0.13.0. Affected by this vulnerability is the function getuserdata of th... |
| CVE-2026-6570 | LOW | 2.7 | 0.3% | Apr 19, 2026 | A security flaw has been discovered in kodcloud KodExplorer up to 4.52. Affected is the function initInstall of the file... |
| CVE-2026-32690 | LOW | 3.7 | 0.4% | Apr 18, 2026 | Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by th... |
| CVE-2026-40341 | LOW | 3.5 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_u... |
| CVE-2026-40336 | LOW | 2.4 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack... |
| CVE-2026-40334 | LOW | 3.5 | 0.2% | Apr 18, 2026 | libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exi... |
| CVE-2026-35402 | LOW | 2.3 | 0.3% | Apr 17, 2026 | mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the ... |
| CVE-2026-6493 | LOW | 3.5 | 0.3% | Apr 17, 2026 | A flaw has been found in lukevella rallly up to 4.7.4. This affects an unknown function of the file apps/web/src/app/[lo... |
| CVE-2026-6486 | LOW | 3.5 | 0.2% | Apr 17, 2026 | A vulnerability was detected in classroombookings up to 2.17.0. This impacts the function read of the file crbs-core/app... |
| CVE-2026-40263 | LOW | 3.7 | 0.2% | Apr 17, 2026 | Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt pa... |
| CVE-2026-41080 | LOW | 2.9 | 0.4% | Apr 16, 2026 | libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document. |
| CVE-2026-3155 | LOW | 3.1 | 0.3% | Apr 16, 2026 | The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and... |
| CVE-2026-40947 | LOW | 2.9 | 0.1% | Apr 16, 2026 | Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search... |
| CVE-2026-6313 | LOW | 3.1 | 0.2% | Apr 15, 2026 | Insufficient policy enforcement in CORS in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compr... |
| CVE-2026-6312 | LOW | 3.1 | 0.2% | Apr 15, 2026 | Insufficient policy enforcement in Passwords in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had ... |
| CVE-2026-33877 | LOW | 3.7 | 0.4% | Apr 15, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions 4.28.0 and prior contain a timing side-chann... |
| CVE-2026-21727 | LOW | 3.3 | 0.2% | Apr 15, 2026 | --- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-le... |
| CVE-2026-33212 | LOW | 3.1 | 0.2% | Apr 15, 2026 | Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending... |
| CVE-2026-27769 | LOW | 2.7 | 0.2% | Apr 15, 2026 | Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Wor... |
| CVE-2026-34454 | LOW | 3.5 | 0.2% | Apr 14, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p... |
| CVE-2026-27308 | LOW | 2.4 | 2.6% | Apr 14, 2026 | ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now