2026 CVE Vulnerabilities
44,810 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48866 | CRITICAL | 9.6 | 0.5% | Jun 1, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravit... |
| CVE-2026-42682 | CRITICAL | 9.1 | 0.3% | Jun 1, 2026 | Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-42680 | CRITICAL | 9.8 | 0.3% | Jun 1, 2026 | Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows P... |
| CVE-2026-0826 | CRITICAL | 9.2 | 24.5% | Jun 1, 2026 | In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could en... |
| CVE-2026-7858 | CRITICAL | 9.8 | 0.5% | Jun 1, 2026 | A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic ... |
| CVE-2026-44825 | CRITICAL | 9.8 | 0.5% | Jun 1, 2026 | Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 throug... |
| CVE-2026-42252 | CRITICAL | 9.1 | 0.4% | Jun 1, 2026 | Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") show... |
| CVE-2026-48188 | CRITICAL | 9.1 | 0.4% | Jun 1, 2026 | An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthe... |
| CVE-2026-10187 | CRITICAL | 9.8 | 1.4% | May 31, 2026 | A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasic... |
| CVE-2026-45700 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an... |
| CVE-2026-45697 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted ... |
| CVE-2026-45372 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's se... |
| CVE-2026-9051 | CRITICAL | 9.3 | 0.6% | May 29, 2026 | There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an ... |
| CVE-2026-47744 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings al... |
| CVE-2026-44650 | CRITICAL | 9.1 | 0.6% | May 29, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-44649 | CRITICAL | 9.8 | 0.2% | May 29, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-7786 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintex... |
| CVE-2026-5386 | CRITICAL | 9.1 | 0.6% | May 29, 2026 | The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an ... |
| CVE-2026-45668 | CRITICAL | 9.3 | 0.2% | May 29, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
| CVE-2026-45661 | CRITICAL | 9.9 | 0.7% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerab... |
| CVE-2026-45633 | CRITICAL | 9.9 | 0.9% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injecti... |
| CVE-2026-45632 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enfor... |
| CVE-2026-45631 | CRITICAL | 10 | 0.4% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SEC... |
| CVE-2026-45630 | CRITICAL | 9 | 0.8% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection... |
| CVE-2026-45629 | CRITICAL | 9.9 | 0.8% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now