2026 CVE Vulnerabilities
49,870 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40909 | MEDIUM | 6.5 | 0.7% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) c... |
| CVE-2026-40908 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root execut... |
| CVE-2026-40907 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/... |
| CVE-2026-40889 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authentica... |
| CVE-2026-40888 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authent... |
| CVE-2026-40874 | MEDIUM | 6 | 0.2% | Apr 21, 2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administr... |
| CVE-2026-40869 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vu... |
| CVE-2026-33812 | MEDIUM | 6.1 | 0.1% | Apr 21, 2026 | Parsing a malicious font file can cause excessive memory allocation. |
| CVE-2026-6744 | MEDIUM | 6.3 | 0.2% | Apr 21, 2026 | A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Hand... |
| CVE-2026-41456 | MEDIUM | 5.1 | 0.4% | Apr 21, 2026 | Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that all... |
| CVE-2026-22751 | MEDIUM | 4.8 | 0.1% | Apr 21, 2026 | Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTok... |
| CVE-2026-41194 | MEDIUM | 5.4 | 0.1% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect act... |
| CVE-2026-40608 | MEDIUM | 5.5 | 0.1% | Apr 21, 2026 | Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the... |
| CVE-2026-40606 | MEDIUM | 4.8 | 0.2% | Apr 21, 2026 | mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw... |
| CVE-2026-40604 | MEDIUM | 4.4 | 0.1% | Apr 21, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the... |
| CVE-2026-40602 | MEDIUM | 5.6 | 0.1% | Apr 21, 2026 | The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assi... |
| CVE-2026-40594 | MEDIUM | 4.8 | 0.2% | Apr 21, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secu... |
| CVE-2026-40587 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profi... |
| CVE-2026-41183 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is... |
| CVE-2026-40592 | MEDIUM | 5.9 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conver... |
| CVE-2026-40590 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal expose... |
| CVE-2026-40574 | MEDIUM | 6.8 | 0.2% | Apr 21, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization b... |
| CVE-2026-40570 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action ... |
| CVE-2026-40567 | MEDIUM | 5.8 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ... |
| CVE-2026-40566 | MEDIUM | 4.1 | 0.3% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forge... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now