2026 CVE Vulnerabilities
49,842 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41062 | MEDIUM | 6.5 | 0.7% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in comm... |
| CVE-2026-41061 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/vide... |
| CVE-2026-41060 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/fun... |
| CVE-2026-41055 | MEDIUM | 5.3 | 0.4% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks p... |
| CVE-2026-40935 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA l... |
| CVE-2026-40929 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mu... |
| CVE-2026-40928 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/... |
| CVE-2026-6830 | MEDIUM | 4.8 | 0.1% | Apr 21, 2026 | nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear envi... |
| CVE-2026-6829 | MEDIUM | 6.3 | 0.3% | Apr 21, 2026 | nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or chan... |
| CVE-2026-6799 | MEDIUM | 6.3 | 1.2% | Apr 21, 2026 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of ... |
| CVE-2026-41527 | MEDIUM | 6.9 | 0.1% | Apr 21, 2026 | KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there i... |
| CVE-2026-40944 | MEDIUM | 6.9 | 0.2% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configurati... |
| CVE-2026-40942 | MEDIUM | 6.3 | 0.3% | Apr 21, 2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr... |
| CVE-2026-40939 | MEDIUM | 6.8 | 0.2% | Apr 21, 2026 | The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr... |
| CVE-2026-1354 | MEDIUM | 6.4 | 0.1% | Apr 21, 2026 | Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bl... |
| CVE-2026-6797 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability is the function Zip... |
| CVE-2026-6796 | MEDIUM | 5.3 | 0.1% | Apr 21, 2026 | A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file cor... |
| CVE-2026-40927 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page,... |
| CVE-2026-40924 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-40923 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-35252 | MEDIUM | 6.4 | 0.2% | Apr 21, 2026 | Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API). Support... |
| CVE-2026-35248 | MEDIUM | 5 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35247 | MEDIUM | 6 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35244 | MEDIUM | 5.2 | 0.2% | Apr 21, 2026 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Manageme... |
| CVE-2026-35241 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now