2026 CVE Vulnerabilities
52,054 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41135 | HIGH | 7.5 | 0.5% | Apr 22, 2026 | free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile c... |
| CVE-2026-41133 | HIGH | 8.8 | 0.3% | Apr 22, 2026 | pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `r... |
| CVE-2026-41059 | HIGH | 8.2 | 0.3% | Apr 22, 2026 | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have ... |
| CVE-2026-5921 | HIGH | 8.9 | 0.4% | Apr 21, 2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t... |
| CVE-2026-4296 | HIGH | 8.8 | 0.3% | Apr 21, 2026 | An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to byp... |
| CVE-2026-41058 | HIGH | 8.1 | 0.5% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `del... |
| CVE-2026-41057 | HIGH | 7.1 | 0.1% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e... |
| CVE-2026-41056 | HIGH | 8.1 | 0.3% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in ... |
| CVE-2026-40926 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/cat... |
| CVE-2026-6832 | HIGH | 8.1 | 0.5% | Apr 21, 2026 | Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authentic... |
| CVE-2026-40945 | HIGH | 8.7 | 0.3% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token... |
| CVE-2026-40943 | HIGH | 8.7 | 0.2% | Apr 21, 2026 | Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing... |
| CVE-2026-40931 | HIGH | 7.8 | 0.2% | Apr 21, 2026 | Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 rel... |
| CVE-2026-40706 | HIGH | 8.4 | 0.2% | Apr 21, 2026 | In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that al... |
| CVE-2026-6823 | HIGH | 8.3 | 0.3% | Apr 21, 2026 | HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote cha... |
| CVE-2026-40938 | HIGH | 8.5 | 0.8% | Apr 21, 2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and... |
| CVE-2026-40925 | HIGH | 8.3 | 0.2% | Apr 21, 2026 | WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also r... |
| CVE-2026-40906 | HIGH | 8.8 | 0.5% | Apr 21, 2026 | Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API... |
| CVE-2026-40905 | HIGH | 8.1 | 0.3% | Apr 21, 2026 | LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisoning vulnerability was ... |
| CVE-2026-40895 | HIGH | 7.5 | 0.5% | Apr 21, 2026 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows... |
| CVE-2026-35251 | HIGH | 7.5 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35246 | HIGH | 7.5 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35245 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-35243 | HIGH | 7.8 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF ... |
| CVE-2026-35242 | HIGH | 7.5 | 0.1% | Apr 21, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now