2026 CVE Vulnerabilities
44,964 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46155 | CRITICAL | 9.1 | 0.5% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb/client: fix out-of-bounds read in smb2_compound... |
| CVE-2026-46137 | CRITICAL | 9.8 | 0.4% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race T... |
| CVE-2026-46135 | CRITICAL | 9.8 | 0.4% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queu... |
| CVE-2026-46119 | CRITICAL | 9.1 | 0.5% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth mess... |
| CVE-2026-46115 | CRITICAL | 9.8 | 0.5% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeable bi... |
| CVE-2026-4408 | CRITICAL | 9.8 | 2.5% | May 28, 2026 | A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain con... |
| CVE-2026-32999 | CRITICAL | 9 | 0.3% | May 28, 2026 | Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant admin... |
| CVE-2026-32998 | CRITICAL | 9.4 | 0.4% | May 28, 2026 | This vulnerability in Veeam Service Provider Console allows for remote code execution. |
| CVE-2026-9739 | CRITICAL | 9.4 | 0.3% | May 27, 2026 | Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-... |
| CVE-2026-45083 | CRITICAL | 9.8 | 0.4% | May 27, 2026 | The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to bef... |
| CVE-2026-8364 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes r... |
| CVE-2026-8363 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with ... |
| CVE-2026-8362 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with... |
| CVE-2026-45102 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm modu... |
| CVE-2026-44888 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile()... |
| CVE-2026-44887 | CRITICAL | 9.8 | 0.5% | May 27, 2026 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based config... |
| CVE-2026-44590 | CRITICAL | 9.3 | 1.1% | May 27, 2026 | Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workfl... |
| CVE-2026-48150 | CRITICAL | 9 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAd... |
| CVE-2026-46425 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches on... |
| CVE-2026-45087 | CRITICAL | 10 | 1.1% | May 27, 2026 | Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started ... |
| CVE-2026-48027 | CRITICAL | 9.8 | 1.8% | May 27, 2026 | Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was publish... |
| CVE-2026-44330 | CRITICAL | 10 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanage... |
| CVE-2026-44329 | CRITICAL | 10 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management... |
| CVE-2026-44327 | CRITICAL | 10 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route... |
| CVE-2026-44326 | CRITICAL | 9.4 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now