2026 CVE Vulnerabilities
44,958 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45787 | CRITICAL | 9.1 | 0.1% | May 28, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic ... |
| CVE-2026-45374 | CRITICAL | 9.6 | 0.3% | May 28, 2026 | CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents... |
| CVE-2026-45323 | CRITICAL | 9.6 | 0.3% | May 28, 2026 | MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered witho... |
| CVE-2026-45311 | CRITICAL | 9.6 | 0.4% | May 28, 2026 | CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in... |
| CVE-2026-45058 | CRITICAL | 9.4 | 0.2% | May 28, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is... |
| CVE-2026-43898 | CRITICAL | 10 | 0.5% | May 28, 2026 | SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing... |
| CVE-2026-9098 | CRITICAL | 9.1 | 0.2% | May 28, 2026 | In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLRe... |
| CVE-2026-9097 | CRITICAL | 9.8 | 0.4% | May 28, 2026 | Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExcha... |
| CVE-2026-9094 | CRITICAL | 9.8 | 0.4% | May 28, 2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExc... |
| CVE-2026-9093 | CRITICAL | 9.8 | 0.4% | May 28, 2026 | In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestrict... |
| CVE-2026-9092 | CRITICAL | 9.1 | 0.3% | May 28, 2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account ... |
| CVE-2026-9090 | CRITICAL | 9.1 | 0.2% | May 28, 2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplyi... |
| CVE-2026-45261 | CRITICAL | 9.3 | 0.5% | May 28, 2026 | GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execut... |
| CVE-2026-44477 | CRITICAL | 9.9 | 0.5% | May 28, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and ... |
| CVE-2026-38707 | CRITICAL | 9.8 | 1.2% | May 28, 2026 | A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firm... |
| CVE-2026-38704 | CRITICAL | 9.8 | 1.3% | May 28, 2026 | A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 ... |
| CVE-2026-38703 | CRITICAL | 9.8 | 1.2% | May 28, 2026 | A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 f... |
| CVE-2026-38702 | CRITICAL | 9.8 | 1.2% | May 28, 2026 | A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 f... |
| CVE-2026-24444 | CRITICAL | 9.8 | 0.5% | May 28, 2026 | SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability ... |
| CVE-2026-44672 | CRITICAL | 9.3 | 0.3% | May 28, 2026 | mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30... |
| CVE-2026-8980 | CRITICAL | 9.3 | 0.3% | May 28, 2026 | The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-priv... |
| CVE-2026-8979 | CRITICAL | 9.3 | 0.6% | May 28, 2026 | The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated re... |
| CVE-2026-9813 | CRITICAL | 9.9 | 0.2% | May 28, 2026 | FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL ... |
| CVE-2026-46195 | CRITICAL | 9.8 | 0.7% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: validate dacloffset before building DA... |
| CVE-2026-46185 | CRITICAL | 9.1 | 0.5% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in symlink_data(... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now