2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24425 | CRITICAL | 9.9 | 0.7% | May 20, 2026 | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface ... |
| CVE-2026-3593 | CRITICAL | 9.8 | 1.8% | May 20, 2026 | A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.... |
| CVE-2026-22314 | CRITICAL | 9 | 0.4% | May 20, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesa... |
| CVE-2026-42960 | CRITICAL | 10 | 0.2% | May 20, 2026 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authori... |
| CVE-2026-33278 | CRITICAL | 9.8 | 1.3% | May 20, 2026 | NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables de... |
| CVE-2026-9065 | CRITICAL | 9.3 | 0.3% | May 20, 2026 | SureCart version prior to 4.2.1 are vulnerable to authenticated SQL injection via multiple parameters ('model_name', 'mo... |
| CVE-2026-9059 | CRITICAL | 9.3 | 0.3% | May 20, 2026 | NextGEN Gallery version prior to 4.2.1 are vulnerable to authenticated SQL injection via the 'orderby' parameter on the ... |
| CVE-2026-7637 | CRITICAL | 9.8 | 0.6% | May 20, 2026 | The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deseria... |
| CVE-2026-24214 | CRITICAL | 9.8 | 0.7% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer ove... |
| CVE-2026-24213 | CRITICAL | 9.8 | 0.7% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-boun... |
| CVE-2026-24207 | CRITICAL | 9.8 | 2.2% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes... |
| CVE-2026-24206 | CRITICAL | 9.8 | 0.5% | May 20, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A succes... |
| CVE-2026-24163 | CRITICAL | 9.8 | 0.6% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deseri... |
| CVE-2026-24142 | CRITICAL | 9.8 | 0.4% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful ex... |
| CVE-2026-7284 | CRITICAL | 9.8 | 0.5% | May 20, 2026 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation ... |
| CVE-2026-6555 | CRITICAL | 9.8 | 1.0% | May 20, 2026 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, ... |
| CVE-2026-8495 | CRITICAL | 9.8 | 0.4% | May 19, 2026 | Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0.... |
| CVE-2026-34234 | CRITICAL | 10 | 0.8% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p... |
| CVE-2026-33642 | CRITICAL | 9.8 | 0.3% | May 19, 2026 | Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kit... |
| CVE-2026-8605 | CRITICAL | 9.8 | 0.4% | May 19, 2026 | In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA syst... |
| CVE-2026-8603 | CRITICAL | 9.8 | 1.3% | May 19, 2026 | In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on t... |
| CVE-2026-8602 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at... |
| CVE-2026-36829 | CRITICAL | 9.8 | 1.3% | May 19, 2026 | An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7.... |
| CVE-2026-37281 | CRITICAL | 9.8 | 1.6% | May 19, 2026 | An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remo... |
| CVE-2026-31072 | CRITICAL | 9.8 | 0.8% | May 19, 2026 | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remot... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now