2026 CVE Vulnerabilities
49,873 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40570 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action ... |
| CVE-2026-40567 | MEDIUM | 5.8 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can ... |
| CVE-2026-40566 | MEDIUM | 4.1 | 0.3% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forge... |
| CVE-2026-40161 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-35451 | MEDIUM | 5.7 | 0.2% | Apr 21, 2026 | Twenty is an open source CRM. Prior to 1.20.6, a Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote... |
| CVE-2026-30452 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | Textpattern CMS 4.9.0 contains a Broken Access Control vulnerability in the article management system that allows authen... |
| CVE-2026-26274 | MEDIUM | 6.6 | 0.2% | Apr 21, 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a vulnerability was identifie... |
| CVE-2026-26067 | MEDIUM | 4.9 | 0.2% | Apr 21, 2026 | October is a Content Management System (CMS) and web platform. Prior to 3.7.14 and 4.1.10, a server-side information dis... |
| CVE-2026-25542 | MEDIUM | 6.5 | 0.3% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 0.43.0 an... |
| CVE-2026-24176 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespa... |
| CVE-2026-40565 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's linkify() function i... |
| CVE-2026-31014 | MEDIUM | 6.3 | 0.1% | Apr 21, 2026 | Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint p... |
| CVE-2026-31013 | MEDIUM | 6.1 | 0.2% | Apr 21, 2026 | Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search paramet... |
| CVE-2026-29644 | MEDIUM | 5.3 | 0.1% | Apr 21, 2026 | XiangShan (open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) h... |
| CVE-2026-1089 | MEDIUM | 6.5 | 0.2% | Apr 21, 2026 | User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup,... |
| CVE-2026-0972 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, det... |
| CVE-2026-0971 | MEDIUM | 4.3 | 0.2% | Apr 21, 2026 | An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web User... |
| CVE-2026-6783 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in ... |
| CVE-2026-6779 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6778 | MEDIUM | 5.3 | 0.3% | Apr 21, 2026 | Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6777 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6775 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6774 | MEDIUM | 5.4 | 0.2% | Apr 21, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
| CVE-2026-6770 | MEDIUM | 6.5 | 4.9% | Apr 21, 2026 | Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunde... |
| CVE-2026-6767 | MEDIUM | 5.3 | 0.2% | Apr 21, 2026 | Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now