2026 CVE Vulnerabilities
49,744 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41136 | MEDIUM | 5.3 | 0.3% | Apr 22, 2026 | free5GC AMF provides Access & Mobility Management Function (AMF) for free5GC, an an open-source project for 5th generati... |
| CVE-2026-41131 | MEDIUM | 5 | 0.1% | Apr 22, 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.14.1, in specific scenarios, mode... |
| CVE-2026-41130 | MEDIUM | 5.5 | 0.3% | Apr 22, 2026 | Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through ... |
| CVE-2026-41129 | MEDIUM | 5.5 | 0.3% | Apr 22, 2026 | Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9... |
| CVE-2026-41128 | MEDIUM | 5.3 | 0.2% | Apr 22, 2026 | Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint... |
| CVE-2026-41127 | MEDIUM | 6.5 | 0.2% | Apr 22, 2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows vie... |
| CVE-2026-41126 | MEDIUM | 4.3 | 0.2% | Apr 22, 2026 | BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/... |
| CVE-2026-40343 | MEDIUM | 5.8 | 10.0% | Apr 22, 2026 | free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core... |
| CVE-2026-5512 | MEDIUM | 4.3 | 0.3% | Apr 21, 2026 | An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacke... |
| CVE-2026-41063 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSa... |
| CVE-2026-41062 | MEDIUM | 6.5 | 0.7% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in comm... |
| CVE-2026-41061 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide... |
| CVE-2026-41060 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/fun... |
| CVE-2026-41055 | MEDIUM | 5.3 | 0.4% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks p... |
| CVE-2026-40935 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l... |
| CVE-2026-40929 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu... |
| CVE-2026-40928 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/... |
| CVE-2026-6830 | MEDIUM | 4.8 | 0.1% | Apr 21, 2026 | nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi... |
| CVE-2026-6829 | MEDIUM | 6.3 | 0.3% | Apr 21, 2026 | nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or chan... |
| CVE-2026-6799 | MEDIUM | 6.3 | 1.2% | Apr 21, 2026 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of ... |
| CVE-2026-41527 | MEDIUM | 6.9 | 0.1% | Apr 21, 2026 | KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there i... |
| CVE-2026-40944 | MEDIUM | 6.9 | 0.2% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configurati... |
| CVE-2026-40942 | MEDIUM | 6.3 | 0.3% | Apr 21, 2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr... |
| CVE-2026-40939 | MEDIUM | 6.8 | 0.2% | Apr 21, 2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr... |
| CVE-2026-1354 | MEDIUM | 6.4 | 0.1% | Apr 21, 2026 | Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now