2026 CVE Vulnerabilities
51,995 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41266 | HIGH | 7.5 | 0.3% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-... |
| CVE-2026-41138 | HIGH | 8.8 | 0.6% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remo... |
| CVE-2026-41137 | HIGH | 8.8 | 1.5% | Apr 23, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent al... |
| CVE-2026-41259 | HIGH | 7.5 | 0.2% | Apr 23, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Masto... |
| CVE-2026-41246 | HIGH | 8.1 | 0.5% | Apr 23, 2026 | Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Cont... |
| CVE-2026-41205 | HIGH | 7.5 | 0.4% | Apr 23, 2026 | Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path trave... |
| CVE-2026-40886 | HIGH | 7.7 | 0.4% | Apr 23, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.... |
| CVE-2026-33694 | HIGH | 7.8 | 0.1% | Apr 23, 2026 | This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privile... |
| CVE-2026-6921 | HIGH | 8.3 | 0.2% | Apr 23, 2026 | Race in GPU in Google Chrome on Windows prior to 147.0.7727.117 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-5039 | HIGH | 8.8 | 0.1% | Apr 23, 2026 | TP-Link TL-WR841N v13 uses DES-CBC encryption in the TDDPv2 debug protocol with a cryptographic key derived from default... |
| CVE-2026-34003 | HIGH | 7.8 | 0.3% | Apr 23, 2026 | A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially craft... |
| CVE-2026-34001 | HIGH | 7.8 | 0.3% | Apr 23, 2026 | A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, sp... |
| CVE-2026-33999 | HIGH | 7.8 | 0.4% | Apr 23, 2026 | A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map ... |
| CVE-2026-41461 | HIGH | 8.5 | 0.3% | Apr 23, 2026 | SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/previe... |
| CVE-2026-35225 | HIGH | 8.7 | 0.4% | Apr 23, 2026 | An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter s... |
| CVE-2026-31532 | HIGH | 7.8 | 0.1% | Apr 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() ... |
| CVE-2026-6903 | HIGH | 8.7 | 0.3% | Apr 23, 2026 | The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access func... |
| CVE-2026-5464 | HIGH | 7.2 | 0.7% | Apr 23, 2026 | The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to... |
| CVE-2026-3259 | HIGH | 7.1 | 0.2% | Apr 23, 2026 | A Generation of Error Message Containing Sensitive Information vulnerability in the Materialized View Refresh mechanism ... |
| CVE-2026-41564 | HIGH | 7.5 | 0.4% | Apr 23, 2026 | CryptX versions before 0.088 for Perl do not reseed the Crypt::PK PRNG state after forking. The Crypt::PK::RSA, Crypt::... |
| CVE-2026-41040 | HIGH | 8.7 | 0.4% | Apr 23, 2026 | GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a crafted input string... |
| CVE-2026-34488 | HIGH | 7.3 | 0.1% | Apr 23, 2026 | IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Librar... |
| CVE-2026-41231 | HIGH | 7.5 | 0.4% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export de... |
| CVE-2026-41230 | HIGH | 8.5 | 0.3% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DN... |
| CVE-2026-41208 | HIGH | 8.8 | 0.6% | Apr 23, 2026 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @papercl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now