2026 CVE Vulnerabilities
44,973 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48700 | CRITICAL | 9.3 | 0.2% | May 22, 2026 | An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI... |
| CVE-2026-33712 | CRITICAL | 10 | 0.3% | May 22, 2026 | Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typeb... |
| CVE-2026-32253 | CRITICAL | 9.8 | 0.3% | May 22, 2026 | Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate a... |
| CVE-2026-39821 | CRITICAL | 9.6 | 0.7% | May 22, 2026 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For e... |
| CVE-2026-9256 | CRITICAL | 9.2 | 10.1% | May 22, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w... |
| CVE-2026-9277 | CRITICAL | 9.2 | 0.8% | May 22, 2026 | shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The ... |
| CVE-2026-8673 | CRITICAL | 9.1 | 0.2% | May 22, 2026 | Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Atta... |
| CVE-2026-8670 | CRITICAL | 9.6 | 0.2% | May 22, 2026 | Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session ID... |
| CVE-2026-44930 | CRITICAL | 9.8 | 0.7% | May 22, 2026 | An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacke... |
| CVE-2026-9054 | CRITICAL | 9.2 | 0.3% | May 22, 2026 | An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel p... |
| CVE-2026-46595 | CRITICAL | 10 | 0.5% | May 22, 2026 | Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal... |
| CVE-2026-42508 | CRITICAL | 9.1 | 0.6% | May 22, 2026 | Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and... |
| CVE-2026-39834 | CRITICAL | 9.1 | 0.5% | May 22, 2026 | When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload ... |
| CVE-2026-39833 | CRITICAL | 9.1 | 0.4% | May 22, 2026 | The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enf... |
| CVE-2026-39832 | CRITICAL | 9.1 | 0.6% | May 22, 2026 | When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serializ... |
| CVE-2026-39831 | CRITICAL | 9.1 | 0.4% | May 22, 2026 | The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did... |
| CVE-2026-39830 | CRITICAL | 9.1 | 0.6% | May 22, 2026 | A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection... |
| CVE-2026-9264 | CRITICAL | 9.3 | 0.2% | May 22, 2026 | A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution an... |
| CVE-2026-34910 | CRITICAL | 10 | 78.6% | May 22, 2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS ... |
| CVE-2026-34909 | CRITICAL | 10 | 2.3% | May 22, 2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a... |
| CVE-2026-34908 | CRITICAL | 10 | 2.5% | May 22, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de... |
| CVE-2026-33000 | CRITICAL | 9.1 | 1.1% | May 22, 2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit... |
| CVE-2026-6960 | CRITICAL | 9.8 | 0.7% | May 21, 2026 | The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in... |
| CVE-2026-48242 | CRITICAL | 9.2 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, data... |
| CVE-2026-48241 | CRITICAL | 9.2 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database ut... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now