2026 CVE Vulnerabilities

51,995 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41266HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-...
CVE-2026-41138HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remo...
CVE-2026-41137HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent al...
CVE-2026-41259HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Masto...
CVE-2026-41246HIGH8.1Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Cont...
CVE-2026-41205HIGH7.5Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path trave...
CVE-2026-40886HIGH7.7Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3....
CVE-2026-33694HIGH7.8This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privile...
CVE-2026-6921HIGH8.3Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandb...
CVE-2026-5039HIGH8.8TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default...
CVE-2026-34003HIGH7.8A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially craft...
CVE-2026-34001HIGH7.8A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, sp...
CVE-2026-33999HIGH7.8A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map ...
CVE-2026-41461HIGH8.5SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/previe...
CVE-2026-35225HIGH8.7An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter s...
CVE-2026-31532HIGH7.8In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() ...
CVE-2026-6903HIGH8.7The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access func...
CVE-2026-5464HIGH7.2The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to...
CVE-2026-3259HIGH7.1A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism ...
CVE-2026-41564HIGH7.5CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. The Crypt::PK::RSA, Crypt::...
CVE-2026-41040HIGH8.7GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a crafted input string...
CVE-2026-34488HIGH7.3IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Librar...
CVE-2026-41231HIGH7.5Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export de...
CVE-2026-41230HIGH8.5Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DN...
CVE-2026-41208HIGH8.8Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @papercl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now