2026 CVE Vulnerabilities
44,965 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44315 | CRITICAL | 9.4 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-manag... |
| CVE-2026-49103 | CRITICAL | 9.4 | 0.3% | May 27, 2026 | Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. Thi... |
| CVE-2026-45570 | CRITICAL | 9.6 | 0.4% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH t... |
| CVE-2026-8175 | CRITICAL | 9.8 | 0.6% | May 27, 2026 | IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 t... |
| CVE-2026-7876 | CRITICAL | 9.1 | 0.3% | May 27, 2026 | IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client m... |
| CVE-2026-7524 | CRITICAL | 9.8 | 0.6% | May 27, 2026 | IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links duri... |
| CVE-2026-46043 | CRITICAL | 9.1 | 0.5% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload_size... |
| CVE-2026-46039 | CRITICAL | 9.8 | 0.4% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxgk: Fix potential integer overflow in length chec... |
| CVE-2026-45988 | CRITICAL | 9.8 | 0.5% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix re-decryption of RESPONSE packets If a ... |
| CVE-2026-45972 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF and double free in s... |
| CVE-2026-45898 | CRITICAL | 9.8 | 0.5% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix workqueue list corruption by removin... |
| CVE-2026-35090 | CRITICAL | 9.3 | 0.6% | May 27, 2026 | In Slican telephone exchanges it is possible to manage the control panel remotely. An unauthenticated attacker can conne... |
| CVE-2026-35087 | CRITICAL | 9.3 | 0.7% | May 27, 2026 | Slican telephone exchanges allow administrative protocol authentication bypass. An attacker can bypass the need to enter... |
| CVE-2026-42761 | CRITICAL | 9.3 | 0.2% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active ... |
| CVE-2026-42758 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privile... |
| CVE-2026-42757 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias... |
| CVE-2026-42756 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP ... |
| CVE-2026-42755 | CRITICAL | 9.3 | 0.2% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 TableOn... |
| CVE-2026-42748 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WPify WPify Woo Czech wpify-woo allows Upload a Web She... |
| CVE-2026-42747 | CRITICAL | 9.3 | 0.2% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Eas... |
| CVE-2026-42740 | CRITICAL | 9.3 | 0.2% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan ... |
| CVE-2026-42731 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allow... |
| CVE-2026-42727 | CRITICAL | 9.3 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active ... |
| CVE-2026-8054 | CRITICAL | 10 | 1.6% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints ... |
| CVE-2026-49002 | CRITICAL | 9.1 | 0.3% | May 27, 2026 | Access control failure means that an application does not effectively check user access permissions, so that unauthorize... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now