2026 CVE Vulnerabilities
51,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41485 | HIGH | 7.7 | 0.4% | Apr 24, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an... |
| CVE-2026-41324 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded me... |
| CVE-2026-41068 | HIGH | 7.7 | 0.3% | Apr 24, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cros... |
| CVE-2026-41317 | HIGH | 7.5 | 0.2% | Apr 24, 2026 | Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-... |
| CVE-2026-41316 | HIGH | 8.1 | 1.1% | Apr 24, 2026 | ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` ... |
| CVE-2026-41309 | HIGH | 8.2 | 0.4% | Apr 24, 2026 | Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are ... |
| CVE-2026-33318 | HIGH | 8.8 | 0.5% | Apr 24, 2026 | Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) ... |
| CVE-2026-33317 | HIGH | 8.7 | 0.2% | Apr 24, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-33208 | HIGH | 8.8 | 0.7% | Apr 24, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /co... |
| CVE-2026-33077 | HIGH | 7.5 | 0.4% | Apr 24, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the old... |
| CVE-2026-32952 | HIGH | 7.5 | 1.0% | Apr 24, 2026 | go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NT... |
| CVE-2026-41325 | HIGH | 8.8 | 0.4% | Apr 24, 2026 | Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perfor... |
| CVE-2026-34587 | HIGH | 8.1 | 0.3% | Apr 24, 2026 | Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control w... |
| CVE-2026-32870 | HIGH | 7.5 | 0.3% | Apr 24, 2026 | Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>... |
| CVE-2026-40623 | HIGH | 8.1 | 0.3% | Apr 24, 2026 | A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameter... |
| CVE-2026-35064 | HIGH | 8.7 | 0.5% | Apr 24, 2026 | A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the... |
| CVE-2026-31952 | HIGH | 8.1 | 0.2% | Apr 24, 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software... |
| CVE-2026-27841 | HIGH | 8.4 | 0.2% | Apr 24, 2026 | A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without p... |
| CVE-2026-6732 | HIGH | 7.5 | 0.6% | Apr 23, 2026 | A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definit... |
| CVE-2026-41361 | HIGH | 7.1 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. ... |
| CVE-2026-41359 | HIGH | 8.8 | 0.2% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write perm... |
| CVE-2026-41355 | HIGH | 7.3 | 0.1% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sand... |
| CVE-2026-41353 | HIGH | 8.1 | 0.3% | Apr 23, 2026 | OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attac... |
| CVE-2026-41352 | HIGH | 8.8 | 0.5% | Apr 23, 2026 | OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node ... |
| CVE-2026-41349 | HIGH | 8.8 | 0.5% | Apr 23, 2026 | OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now