2026 CVE Vulnerabilities

49,870 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40909MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) c...
CVE-2026-40908MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root execut...
CVE-2026-40907MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/...
CVE-2026-40889MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authentica...
CVE-2026-40888MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authent...
CVE-2026-40874MEDIUM6mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administr...
CVE-2026-40869MEDIUM6.5Decidim is a participatory democracy framework. Starting in version 0.19.0 and prior to versions 0.30.5 and 0.31.1, a vu...
CVE-2026-33812MEDIUM6.1Parsing a malicious font file can cause excessive memory allocation.
CVE-2026-6744MEDIUM6.3A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Hand...
CVE-2026-41456MEDIUM5.1Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that all...
CVE-2026-22751MEDIUM4.8Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTok...
CVE-2026-41194MEDIUM5.4FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect act...
CVE-2026-40608MEDIUM5.5Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the...
CVE-2026-40606MEDIUM4.8mitmproxy is a interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers and mitmw...
CVE-2026-40604MEDIUM4.4ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.6, the...
CVE-2026-40602MEDIUM5.6The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assi...
CVE-2026-40594MEDIUM4.8pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev98, the set_session_cookie_secu...
CVE-2026-40587MEDIUM6.5blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profi...
CVE-2026-41183MEDIUM4.3FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is...
CVE-2026-40592MEDIUM5.9FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conver...
CVE-2026-40590MEDIUM4.3FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal expose...
CVE-2026-40574MEDIUM6.8OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization b...
CVE-2026-40570MEDIUM5.7FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action ...
CVE-2026-40567MEDIUM5.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ...
CVE-2026-40566MEDIUM4.1FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forge...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now