2026 CVE Vulnerabilities
44,967 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8760 | CRITICAL | 9.8 | 0.6% | May 27, 2026 | The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6... |
| CVE-2026-8450 | CRITICAL | 9.1 | 1.5% | May 27, 2026 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string arg... |
| CVE-2026-44985 | CRITICAL | 9.6 | 0.2% | May 26, 2026 | Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach ... |
| CVE-2026-44966 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pol... |
| CVE-2026-44895 | CRITICAL | 9.2 | 0.4% | May 26, 2026 | GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships... |
| CVE-2026-44451 | CRITICAL | 9.3 | 0.2% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied... |
| CVE-2026-44450 | CRITICAL | 9.9 | 0.4% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command... |
| CVE-2026-44449 | CRITICAL | 9.1 | 0.5% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the ... |
| CVE-2026-44444 | CRITICAL | 9.1 | 0.4% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install... |
| CVE-2026-48689 | CRITICAL | 9.8 | 0.7% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffe... |
| CVE-2026-3660 | CRITICAL | 9.8 | 0.6% | May 26, 2026 | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update se... |
| CVE-2026-9170 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper in... |
| CVE-2026-8856 | CRITICAL | 9.1 | 0.2% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to ... |
| CVE-2026-8855 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mut... |
| CVE-2026-8633 | CRITICAL | 9.8 | 0.8% | May 26, 2026 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server... |
| CVE-2026-7251 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network... |
| CVE-2026-47202 | CRITICAL | 9.3 | 0.2% | May 26, 2026 | Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unau... |
| CVE-2026-46624 | CRITICAL | 9.9 | 0.5% | May 26, 2026 | Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in ... |
| CVE-2026-44668 | CRITICAL | 9.8 | 0.4% | May 26, 2026 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the aut... |
| CVE-2026-48904 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. |
| CVE-2026-48902 | CRITICAL | 9.8 | 0.2% | May 26, 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't e... |
| CVE-2026-48899 | CRITICAL | 9.8 | 0.2% | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. |
| CVE-2026-48898 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. |
| CVE-2026-48691 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp... |
| CVE-2026-45721 | CRITICAL | 9 | 0.4% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now