2026 CVE Vulnerabilities

52,080 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40879HIGH7.5Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends man...
CVE-2026-40876HIGH8.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-ba...
CVE-2026-40875HIGH7mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user das...
CVE-2026-40873HIGH8.9mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quaranti...
CVE-2026-40871HIGH7.2mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-or...
CVE-2026-40870HIGH7.5Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the r...
CVE-2026-33813HIGH7.5Parsing a WEBP image with an invalid, large size panics on 32-bit platforms.
CVE-2026-40868HIGH8.1Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall serv...
CVE-2026-40867HIGH7.1Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerabili...
CVE-2026-40866HIGH8.6Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference...
CVE-2026-40865HIGH7.1Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference...
CVE-2026-40614HIGH8.8PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer ov...
CVE-2026-40613HIGH7.5Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing fu...
CVE-2026-41192HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust ...
CVE-2026-40611HIGH8.8Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in l...
CVE-2026-40599HIGH7.1ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, Cle...
CVE-2026-40588HIGH8.1blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit...
CVE-2026-41191HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave...
CVE-2026-41190HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CON...
CVE-2026-41189HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is autho...
CVE-2026-40591HIGH7.1FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation ...
CVE-2026-40589HIGH7.6FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit ...
CVE-2026-40586HIGH7.5blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of...
CVE-2026-40585HIGH7.4blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-charac...
CVE-2026-40584HIGH7.5RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now