2026 CVE Vulnerabilities
44,969 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44723 | CRITICAL | 9.9 | 0.5% | May 26, 2026 | Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pul... |
| CVE-2026-40383 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. |
| CVE-2026-35223 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | An improper access check allows unauthorized access to com_config webservice endpoints. |
| CVE-2026-35222 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. |
| CVE-2026-35221 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. |
| CVE-2026-2264 | CRITICAL | 9.2 | 0.4% | May 26, 2026 | A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side ... |
| CVE-2026-24212 | CRITICAL | 9.8 | 0.7% | May 26, 2026 | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A s... |
| CVE-2026-48687 | CRITICAL | 9.8 | 1.6% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integrat... |
| CVE-2026-48686 | CRITICAL | 9.8 | 0.6% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachab... |
| CVE-2026-4480 | CRITICAL | 9 | 12.8% | May 26, 2026 | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the comma... |
| CVE-2026-45247 | CRITICAL | 9.8 | 27.5% | May 26, 2026 | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that ... |
| CVE-2026-9543 | CRITICAL | 9.8 | 2.1% | May 26, 2026 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the fi... |
| CVE-2026-7374 | CRITICAL | 9.9 | 0.6% | May 26, 2026 | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with ed... |
| CVE-2026-42496 | CRITICAL | 9.1 | 0.4% | May 26, 2026 | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction dire... |
| CVE-2026-8376 | CRITICAL | 9.8 | 0.4% | May 26, 2026 | Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed strin... |
| CVE-2026-42774 | CRITICAL | 9.3 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngi... |
| CVE-2026-42773 | CRITICAL | 9.3 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOn... |
| CVE-2026-9478 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the... |
| CVE-2026-9477 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDe... |
| CVE-2026-9476 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPassw... |
| CVE-2026-9475 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the f... |
| CVE-2026-9458 | CRITICAL | 9.8 | 2.1% | May 25, 2026 | A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg o... |
| CVE-2026-9457 | CRITICAL | 9.8 | 2.1% | May 25, 2026 | A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmw... |
| CVE-2026-9058 | CRITICAL | 9.3 | 0.3% | May 25, 2026 | For untrusted certificates that contain the "Authority Information Access - caIssuers URI" extension, Szafir SDK will au... |
| CVE-2026-9456 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now