2026 CVE Vulnerabilities

49,873 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-40570MEDIUM5.7FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action ...
CVE-2026-40567MEDIUM5.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ...
CVE-2026-40566MEDIUM4.1FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forge...
CVE-2026-40161MEDIUM6.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...
CVE-2026-35451MEDIUM5.7Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote...
CVE-2026-30452MEDIUM6.5Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authen...
CVE-2026-26274MEDIUM6.6October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identifie...
CVE-2026-26067MEDIUM4.9October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information dis...
CVE-2026-25542MEDIUM6.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 an...
CVE-2026-24176MEDIUM4.3NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespa...
CVE-2026-40565MEDIUM6.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function i...
CVE-2026-31014MEDIUM6.3Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint p...
CVE-2026-31013MEDIUM6.1Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search paramet...
CVE-2026-29644MEDIUM5.3XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) h...
CVE-2026-1089MEDIUM6.5User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup,...
CVE-2026-0972MEDIUM5.4HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, det...
CVE-2026-0971MEDIUM4.3An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web User...
CVE-2026-6783MEDIUM5.3Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in ...
CVE-2026-6779MEDIUM5.3Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6778MEDIUM5.3Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6777MEDIUM5.3Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6775MEDIUM5.3Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6774MEDIUM5.4Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
CVE-2026-6770MEDIUM6.5Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunde...
CVE-2026-6767MEDIUM5.3Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now