2026 CVE Vulnerabilities
44,976 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31071 | CRITICAL | 9.1 | 0.5% | May 19, 2026 | API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated... |
| CVE-2026-31070 | CRITICAL | 9.8 | 0.5% | May 19, 2026 | The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileg... |
| CVE-2026-30118 | CRITICAL | 9.8 | 0.5% | May 19, 2026 | scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of... |
| CVE-2026-30117 | CRITICAL | 9.8 | 0.5% | May 19, 2026 | scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parame... |
| CVE-2026-8711 | CRITICAL | 9.8 | 0.9% | May 19, 2026 | NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled... |
| CVE-2026-44159 | CRITICAL | 9.8 | 0.5% | May 19, 2026 | Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the c... |
| CVE-2026-2587 | CRITICAL | 9.6 | 0.6% | May 19, 2026 | A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used... |
| CVE-2026-2586 | CRITICAL | 9.1 | 0.8% | May 19, 2026 | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user ... |
| CVE-2026-8959 | CRITICAL | 9.6 | 0.4% | May 19, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire... |
| CVE-2026-8956 | CRITICAL | 9.8 | 0.6% | May 19, 2026 | Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thun... |
| CVE-2026-8953 | CRITICAL | 9.6 | 0.5% | May 19, 2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15... |
| CVE-2026-8950 | CRITICAL | 9.3 | 0.2% | May 19, 2026 | Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14... |
| CVE-2026-8948 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird ... |
| CVE-2026-47323 | CRITICAL | 9.8 | 1.4% | May 19, 2026 | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra... |
| CVE-2026-43633 | CRITICAL | 10 | 1.1% | May 19, 2026 | HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a ... |
| CVE-2026-4883 | CRITICAL | 9.8 | 0.8% | May 19, 2026 | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the... |
| CVE-2026-43493 | CRITICAL | 9.8 | 0.6% | May 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG reques... |
| CVE-2026-46725 | CRITICAL | 9.2 | 2.3% | May 19, 2026 | The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. ... |
| CVE-2026-45434 | CRITICAL | 9.8 | 22.9% | May 19, 2026 | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution T... |
| CVE-2026-41919 | CRITICAL | 9.1 | 0.5% | May 19, 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi... |
| CVE-2026-31986 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U... |
| CVE-2026-2611 | CRITICAL | 9.6 | 0.4% | May 19, 2026 | In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. ... |
| CVE-2026-4885 | CRITICAL | 9.8 | 1.0% | May 19, 2026 | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ... |
| CVE-2026-47314 | CRITICAL | 9.8 | 0.3% | May 19, 2026 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:... |
| CVE-2026-47311 | CRITICAL | 9.8 | 0.3% | May 19, 2026 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now