2026 CVE Vulnerabilities
49,010 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4502 | MEDIUM | 6.5 | 0.3% | Apr 30, 2026 | IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the s... |
| CVE-2026-41174 | MEDIUM | 6.4 | 0.3% | Apr 30, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potent... |
| CVE-2026-40951 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with loc... |
| CVE-2026-40950 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of... |
| CVE-2026-40949 | MEDIUM | 4.4 | 0.1% | Apr 30, 2026 | CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo... |
| CVE-2026-3346 | MEDIUM | 6.4 | 0.2% | Apr 30, 2026 | IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows... |
| CVE-2026-3340 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo... |
| CVE-2026-33452 | MEDIUM | 5.5 | 0.1% | Apr 30, 2026 | CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with lo... |
| CVE-2026-33450 | MEDIUM | 5.5 | 0.2% | Apr 30, 2026 | CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with ... |
| CVE-2026-28532 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing... |
| CVE-2026-7429 | MEDIUM | 4.6 | 0.2% | Apr 30, 2026 | SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attacker... |
| CVE-2026-40603 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-35514 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-32148 | MEDIUM | 5.9 | 0.2% | Apr 30, 2026 | Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency... |
| CVE-2026-36766 | MEDIUM | 5.4 | 0.1% | Apr 30, 2026 | Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer ... |
| CVE-2026-36763 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 al... |
| CVE-2026-36761 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers... |
| CVE-2026-36764 | MEDIUM | 5 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows aut... |
| CVE-2026-36757 | MEDIUM | 4.3 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authentica... |
| CVE-2026-38940 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code ... |
| CVE-2026-38939 | MEDIUM | 6.1 | 0.2% | Apr 30, 2026 | Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code... |
| CVE-2026-36759 | MEDIUM | 6.5 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticat... |
| CVE-2026-36758 | MEDIUM | 4.3 | 0.2% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated at... |
| CVE-2026-36756 | MEDIUM | 5.4 | 0.1% | Apr 30, 2026 | A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated a... |
| CVE-2026-7500 | MEDIUM | 5.4 | 0.2% | Apr 30, 2026 | When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now