2026 CVE Vulnerabilities
50,562 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40242 | MEDIUM | 6.5 | 0.6% | Apr 10, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/template... |
| CVE-2026-40191 | MEDIUM | 6.8 | 0.1% | Apr 10, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta... |
| CVE-2026-40185 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo m... |
| CVE-2026-40184 | MEDIUM | 5.3 | 0.2% | Apr 10, 2026 | TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. Th... |
| CVE-2026-40178 | MEDIUM | 5.9 | 0.2% | Apr 10, 2026 | ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a... |
| CVE-2026-40175 | MEDIUM | 4.8 | 1.9% | Apr 10, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a... |
| CVE-2026-39922 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vuln... |
| CVE-2026-39921 | MEDIUM | 6.3 | 0.2% | Apr 10, 2026 | GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows a... |
| CVE-2026-3446 | MEDIUM | 6 | 0.2% | Apr 10, 2026 | When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded... |
| CVE-2026-33737 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string()... |
| CVE-2026-33736 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can en... |
| CVE-2026-33708 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns... |
| CVE-2026-33705 | MEDIUM | 5.3 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ ... |
| CVE-2026-33703 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerabili... |
| CVE-2026-27460 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a c... |
| CVE-2026-33141 | MEDIUM | 6.5 | 0.1% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerabili... |
| CVE-2026-32932 | MEDIUM | 6.1 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the sess... |
| CVE-2026-32893 | MEDIUM | 5.4 | 0.1% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability i... |
| CVE-2026-31941 | MEDIUM | 6.5 | 0.2% | Apr 10, 2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request... |
| CVE-2026-1502 | MEDIUM | 5.7 | 0.6% | Apr 10, 2026 | CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. |
| CVE-2026-40160 | MEDIUM | 6.5 | 0.3% | Apr 10, 2026 | PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied UR... |
| CVE-2026-40159 | MEDIUM | 5.5 | 0.2% | Apr 10, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows s... |
| CVE-2026-40103 | MEDIUM | 5.4 | 0.2% | Apr 10, 2026 | Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's scoped API token enforcement f... |
| CVE-2026-40100 | MEDIUM | 5.3 | 0.3% | Apr 10, 2026 | FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitr... |
| CVE-2026-40086 | MEDIUM | 5.3 | 0.6% | Apr 10, 2026 | Rembg is a tool to remove images background. Prior to 2.0.75, a path traversal vulnerability in the rembg HTTP server al... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now