2026 CVE Vulnerabilities
52,116 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6759 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderb... |
| CVE-2026-6758 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150... |
| CVE-2026-6756 | HIGH | 7.5 | 0.2% | Apr 21, 2026 | Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150. |
| CVE-2026-6754 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Fire... |
| CVE-2026-6753 | HIGH | 7.3 | 0.3% | Apr 21, 2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, ... |
| CVE-2026-6752 | HIGH | 7.3 | 0.3% | Apr 21, 2026 | Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, ... |
| CVE-2026-6751 | HIGH | 7.3 | 0.3% | Apr 21, 2026 | Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR ... |
| CVE-2026-6750 | HIGH | 8.8 | 0.5% | Apr 21, 2026 | Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.... |
| CVE-2026-6749 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in ... |
| CVE-2026-6747 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150... |
| CVE-2026-6746 | HIGH | 7.5 | 0.6% | Apr 21, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef... |
| CVE-2026-40520 | HIGH | 8.8 | 1.4% | Apr 21, 2026 | FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() fun... |
| CVE-2026-41039 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration i... |
| CVE-2026-41038 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-b... |
| CVE-2026-6553 | HIGH | 7.5 | 0.2% | Apr 21, 2026 | Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and u... |
| CVE-2026-41037 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed logi... |
| CVE-2026-41036 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the manage... |
| CVE-2026-39467 | HIGH | 7.2 | 0.4% | Apr 21, 2026 | Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.Th... |
| CVE-2026-31368 | HIGH | 7.8 | 0.1% | Apr 21, 2026 | AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service avail... |
| CVE-2026-40497 | HIGH | 8.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDanger... |
| CVE-2026-40250 | HIGH | 7.1 | 0.4% | Apr 21, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-40244 | HIGH | 7.1 | 0.4% | Apr 21, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-39973 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability... |
| CVE-2026-39866 | HIGH | 8.8 | 2.3% | Apr 21, 2026 | Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command... |
| CVE-2026-39386 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now