2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48241 | CRITICAL | 9.2 | 0.3% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database ut... |
| CVE-2026-48207 | CRITICAL | 9.8 | 0.6% | May 21, 2026 | Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented Deserializati... |
| CVE-2026-39531 | CRITICAL | 9.3 | 0.2% | May 21, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W... |
| CVE-2026-5118 | CRITICAL | 9.8 | 0.5% | May 21, 2026 | The Divi Form Builder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.2... |
| CVE-2026-43501 | CRITICAL | 9.8 | 0.5% | May 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompress... |
| CVE-2026-5433 | CRITICAL | 9.1 | 0.9% | May 21, 2026 | Honeywell Control Network Module (CNM) contains command injection vulnerability in the web interface. An attacker could ... |
| CVE-2026-4858 | CRITICAL | 9.9 | 0.2% | May 21, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration ... |
| CVE-2026-44050 | CRITICAL | 9.9 | 0.4% | May 21, 2026 | A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote auth... |
| CVE-2026-6279 | CRITICAL | 9.8 | 2.2% | May 21, 2026 | The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP F... |
| CVE-2026-9152 | CRITICAL | 10 | 0.3% | May 21, 2026 | A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search ind... |
| CVE-2026-48172 | CRITICAL | 9.8 | 18.9% | May 21, 2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild i... |
| CVE-2026-47372 | CRITICAL | 9.1 | 0.4% | May 20, 2026 | Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the buil... |
| CVE-2026-8631 | CRITICAL | 9.8 | 1.7% | May 20, 2026 | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vul... |
| CVE-2026-9141 | CRITICAL | 9.8 | 0.5% | May 20, 2026 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web... |
| CVE-2026-9139 | CRITICAL | 9.8 | 0.5% | May 20, 2026 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web ... |
| CVE-2026-9129 | CRITICAL | 9.4 | 0.2% | May 20, 2026 | A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling ... |
| CVE-2026-9102 | CRITICAL | 9.4 | 0.6% | May 20, 2026 | A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitiza... |
| CVE-2026-9082 | CRITICAL | 9.8 | 84.6% | May 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Drupal core... |
| CVE-2026-45444 | CRITICAL | 10 | 0.3% | May 20, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using M... |
| CVE-2026-39405 | CRITICAL | 9.4 | 0.3% | May 20, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.... |
| CVE-2026-33137 | CRITICAL | 9.3 | 0.6% | May 20, 2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ... |
| CVE-2026-23734 | CRITICAL | 9.3 | 19.5% | May 20, 2026 | XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to ... |
| CVE-2026-20223 | CRITICAL | 10 | 0.8% | May 20, 2026 | A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthentica... |
| CVE-2026-8598 | CRITICAL | 9.1 | 0.5% | May 20, 2026 | An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not requi... |
| CVE-2026-8467 | CRITICAL | 9.5 | 0.9% | May 20, 2026 | Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now