2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41430 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-... |
| CVE-2026-41319 | MEDIUM | 5.9 | 0.2% | Apr 24, 2026 | MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in ... |
| CVE-2026-41318 | MEDIUM | 5.4 | 0.2% | Apr 24, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-2028 | MEDIUM | 5.3 | 0.3% | Apr 24, 2026 | The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file owne... |
| CVE-2026-41305 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ... |
| CVE-2026-40254 | MEDIUM | 6.1 | 0.2% | Apr 24, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path... |
| CVE-2026-40099 | MEDIUM | 6.5 | 0.3% | Apr 24, 2026 | Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor... |
| CVE-2026-31956 | MEDIUM | 4.3 | 0.3% | Apr 24, 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software... |
| CVE-2026-31955 | MEDIUM | 4.9 | 0.3% | Apr 24, 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software... |
| CVE-2026-31953 | MEDIUM | 5.4 | 0.1% | Apr 24, 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software... |
| CVE-2026-40431 | MEDIUM | 6.9 | 0.2% | Apr 24, 2026 | A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all adm... |
| CVE-2026-29197 | MEDIUM | 4.3 | 0.2% | Apr 24, 2026 | In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/log... |
| CVE-2026-29050 | MEDIUM | 6.1 | 0.1% | Apr 24, 2026 | melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version ... |
| CVE-2026-25720 | MEDIUM | 5.4 | 0.3% | Apr 24, 2026 | A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allo... |
| CVE-2026-1789 | MEDIUM | 6.9 | 0.3% | Apr 24, 2026 | A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive informat... |
| CVE-2026-41360 | MEDIUM | 6.7 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operan... |
| CVE-2026-41358 | MEDIUM | 5.4 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to ... |
| CVE-2026-41356 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previ... |
| CVE-2026-41354 | MEDIUM | 5.3 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows leg... |
| CVE-2026-41351 | MEDIUM | 6.3 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Bas... |
| CVE-2026-41350 | MEDIUM | 5.3 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to ... |
| CVE-2026-41348 | MEDIUM | 5.4 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths... |
| CVE-2026-41345 | MEDIUM | 6 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Aut... |
| CVE-2026-41343 | MEDIUM | 6.9 | 0.5% | Apr 23, 2026 | OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers... |
| CVE-2026-41341 | MEDIUM | 5.4 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now