2026 CVE Vulnerabilities

52,006 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41230HIGH8.5Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DN...
CVE-2026-41208HIGH8.8Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @papercl...
CVE-2026-41206HIGH7.8PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The...
CVE-2026-41200HIGH8.5STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Infor...
CVE-2026-41180HIGH7.5PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/...
CVE-2026-40062HIGH8.7A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sen...
CVE-2026-32679HIGH8.4The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the...
CVE-2026-41455HIGH8.5WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL...
CVE-2026-41454HIGH8.7WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authe...
CVE-2026-41175HIGH8.1Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulatin...
CVE-2026-41172HIGH7.3Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSR...
CVE-2026-41171HIGH7.3Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a...
CVE-2026-41170HIGH7.2Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `R...
CVE-2026-40517HIGH8.4radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows...
CVE-2026-41166HIGH7OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one K...
CVE-2026-41134HIGH7.8Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generat...
CVE-2026-40937HIGH8.3RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin...
CVE-2026-40882HIGH7.6OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses a...
CVE-2026-33733HIGH7.2EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template manag...
CVE-2026-34065HIGH7.5nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prio...
CVE-2026-34064HIGH8.2nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingCon...
CVE-2026-34063HIGH7.5Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` disco...
CVE-2026-34414HIGH7.1Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connecto...
CVE-2026-34413HIGH8.8Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector...
CVE-2026-5816HIGH8.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now