2026 CVE Vulnerabilities
52,006 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41230 | HIGH | 8.5 | 0.3% | Apr 23, 2026 | Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DN... |
| CVE-2026-41208 | HIGH | 8.8 | 0.6% | Apr 23, 2026 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @papercl... |
| CVE-2026-41206 | HIGH | 7.8 | 0.2% | Apr 23, 2026 | PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The... |
| CVE-2026-41200 | HIGH | 8.5 | 0.3% | Apr 23, 2026 | STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Infor... |
| CVE-2026-41180 | HIGH | 7.5 | 0.3% | Apr 23, 2026 | PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/... |
| CVE-2026-40062 | HIGH | 8.7 | 0.6% | Apr 23, 2026 | A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sen... |
| CVE-2026-32679 | HIGH | 8.4 | 0.2% | Apr 23, 2026 | The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the... |
| CVE-2026-41455 | HIGH | 8.5 | 0.2% | Apr 22, 2026 | WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL... |
| CVE-2026-41454 | HIGH | 8.7 | 0.3% | Apr 22, 2026 | WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authe... |
| CVE-2026-41175 | HIGH | 8.1 | 0.3% | Apr 22, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulatin... |
| CVE-2026-41172 | HIGH | 7.3 | 0.2% | Apr 22, 2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, an SSR... |
| CVE-2026-41171 | HIGH | 7.3 | 0.2% | Apr 22, 2026 | Squidex is an open source headless content management system and content management hub. Versions prior to 7.23.0 have a... |
| CVE-2026-41170 | HIGH | 7.2 | 0.2% | Apr 22, 2026 | Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the `R... |
| CVE-2026-40517 | HIGH | 8.4 | 1.1% | Apr 22, 2026 | radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows... |
| CVE-2026-41166 | HIGH | 7 | 0.3% | Apr 22, 2026 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one K... |
| CVE-2026-41134 | HIGH | 7.8 | 0.4% | Apr 22, 2026 | Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generat... |
| CVE-2026-40937 | HIGH | 8.3 | 0.3% | Apr 22, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-alpha.94, all four notification target admin... |
| CVE-2026-40882 | HIGH | 7.6 | 0.2% | Apr 22, 2026 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses a... |
| CVE-2026-33733 | HIGH | 7.2 | 0.4% | Apr 22, 2026 | EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template manag... |
| CVE-2026-34065 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prio... |
| CVE-2026-34064 | HIGH | 8.2 | 0.3% | Apr 22, 2026 | nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingCon... |
| CVE-2026-34063 | HIGH | 7.5 | 0.4% | Apr 22, 2026 | Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` disco... |
| CVE-2026-34414 | HIGH | 7.1 | 2.8% | Apr 22, 2026 | Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connecto... |
| CVE-2026-34413 | HIGH | 8.8 | 2.8% | Apr 22, 2026 | Xerte Online Toolkits versions 3.15 and earlier contain a missing authentication vulnerability in the elFinder connector... |
| CVE-2026-5816 | HIGH | 8.1 | 0.4% | Apr 22, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now