2026 CVE Vulnerabilities
52,167 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6749 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in ... |
| CVE-2026-6747 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150... |
| CVE-2026-6746 | HIGH | 7.5 | 0.6% | Apr 21, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firef... |
| CVE-2026-40520 | HIGH | 8.8 | 1.4% | Apr 21, 2026 | FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() fun... |
| CVE-2026-41039 | HIGH | 7.5 | 0.3% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to improper access control and insecure default configuration i... |
| CVE-2026-41038 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to lack of enforcement of strong password policies in the web-b... |
| CVE-2026-6553 | HIGH | 7.5 | 0.2% | Apr 21, 2026 | Changing backend users' passwords via the user settings module results in storing the cleartext password in the uc and u... |
| CVE-2026-41037 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to missing rate limiting and CAPTCHA protection for failed logi... |
| CVE-2026-41036 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | This vulnerability exists in Quantum Networks router due to inadequate sanitization of user-supplied input in the manage... |
| CVE-2026-39467 | HIGH | 7.2 | 0.4% | Apr 21, 2026 | Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.Th... |
| CVE-2026-31368 | HIGH | 7.8 | 0.1% | Apr 21, 2026 | AiAssistant is affected by type privilege bypass, successful exploitation of this vulnerability may affect service avail... |
| CVE-2026-40497 | HIGH | 8.1 | 0.2% | Apr 21, 2026 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDanger... |
| CVE-2026-40250 | HIGH | 7.1 | 0.4% | Apr 21, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-40244 | HIGH | 7.1 | 0.4% | Apr 21, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-39973 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | Apktool is a tool for reverse engineering Android APK files. In versions 3.0.0 and 3.0.1, a path traversal vulnerability... |
| CVE-2026-39866 | HIGH | 8.8 | 2.3% | Apr 21, 2026 | Lawnchair is a free, open-source home app for Android. Prior to commit fcba413f55dd47f8a3921445252849126c6266b2, command... |
| CVE-2026-39386 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | Neko is a a self-hosted virtual browser that runs in Docker and uses WebRTC In versions 3.0.0 through 3.0.10 and 3.1.0 t... |
| CVE-2026-39320 | HIGH | 7.5 | 0.4% | Apr 21, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.25.0 are vulnerable to... |
| CVE-2026-41303 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows n... |
| CVE-2026-41299 | HIGH | 7.1 | 0.2% | Apr 21, 2026 | OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only ... |
| CVE-2026-41297 | HIGH | 7.6 | 0.2% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functi... |
| CVE-2026-41296 | HIGH | 8.8 | 0.2% | Apr 21, 2026 | OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile f... |
| CVE-2026-41295 | HIGH | 8.5 | 0.1% | Apr 21, 2026 | OpenClaw before 2026.4.2 contains an improper trust boundary vulnerability allowing untrusted workspace channel shadows ... |
| CVE-2026-41294 | HIGH | 8.6 | 0.1% | Apr 21, 2026 | OpenClaw before 2026.3.28 loads the current working directory .env file before trusted state-dir configuration, allowing... |
| CVE-2026-35587 | HIGH | 8.8 | 0.4% | Apr 21, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now