2026 CVE Vulnerabilities
52,080 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40879 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends man... |
| CVE-2026-40876 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-ba... |
| CVE-2026-40875 | HIGH | 7 | 0.2% | Apr 21, 2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user das... |
| CVE-2026-40873 | HIGH | 8.9 | 0.3% | Apr 21, 2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quaranti... |
| CVE-2026-40871 | HIGH | 7.2 | 9.9% | Apr 21, 2026 | mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-or... |
| CVE-2026-40870 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Decidim is a participatory democracy framework. Starting in version 0.0.1 and prior to versions 0.30.5 and 0.31.1, the r... |
| CVE-2026-33813 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | Parsing a WEBP image with an invalid, large size panics on 32-bit platforms. |
| CVE-2026-40868 | HIGH | 8.1 | 0.3% | Apr 21, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall serv... |
| CVE-2026-40867 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerabili... |
| CVE-2026-40866 | HIGH | 8.6 | 0.2% | Apr 21, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference... |
| CVE-2026-40865 | HIGH | 7.1 | 0.1% | Apr 21, 2026 | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference... |
| CVE-2026-40614 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is a buffer ov... |
| CVE-2026-40613 | HIGH | 7.5 | 1.1% | Apr 21, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.10.0, the STUN/TURN attribute parsing fu... |
| CVE-2026-41192 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust ... |
| CVE-2026-40611 | HIGH | 8.8 | 0.3% | Apr 21, 2026 | Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in l... |
| CVE-2026-40599 | HIGH | 7.1 | 0.1% | Apr 21, 2026 | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.5, Cle... |
| CVE-2026-40588 | HIGH | 8.1 | 0.2% | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the password change form at /profile/{slug}/edit... |
| CVE-2026-41191 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave... |
| CVE-2026-41190 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CON... |
| CVE-2026-41189 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is autho... |
| CVE-2026-40591 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation ... |
| CVE-2026-40589 | HIGH | 7.6 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit ... |
| CVE-2026-40586 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, the login form handler performs no throttling of... |
| CVE-2026-40585 | HIGH | 7.4 | 0.2% | Apr 21, 2026 | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a password reset is initiated, a 128-charac... |
| CVE-2026-40584 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now