2026 CVE Vulnerabilities
44,991 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43493 | CRITICAL | 9.8 | 0.6% | May 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG reques... |
| CVE-2026-46725 | CRITICAL | 9.2 | 2.3% | May 19, 2026 | The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. ... |
| CVE-2026-45434 | CRITICAL | 9.8 | 22.9% | May 19, 2026 | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution T... |
| CVE-2026-41919 | CRITICAL | 9.1 | 0.5% | May 19, 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi... |
| CVE-2026-31986 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U... |
| CVE-2026-2611 | CRITICAL | 9.6 | 0.4% | May 19, 2026 | In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. ... |
| CVE-2026-4885 | CRITICAL | 9.8 | 1.0% | May 19, 2026 | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ... |
| CVE-2026-47314 | CRITICAL | 9.8 | 0.3% | May 19, 2026 | Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot:... |
| CVE-2026-47311 | CRITICAL | 9.8 | 0.3% | May 19, 2026 | Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Es... |
| CVE-2026-47310 | CRITICAL | 9.8 | 0.3% | May 19, 2026 | Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: ... |
| CVE-2026-8838 | CRITICAL | 9.8 | 0.8% | May 18, 2026 | Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver befor... |
| CVE-2026-27130 | CRITICAL | 9.9 | 1.0% | May 18, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection throu... |
| CVE-2026-25244 | CRITICAL | 9.8 | 2.8% | May 18, 2026 | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appiu... |
| CVE-2026-8836 | CRITICAL | 9.8 | 1.0% | May 18, 2026 | A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/sn... |
| CVE-2026-45495 | CRITICAL | 9.8 | 1.0% | May 18, 2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-45230 | CRITICAL | 9.1 | 0.6% | May 18, 2026 | DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelet... |
| CVE-2026-42822 | CRITICAL | 10 | 0.5% | May 18, 2026 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges ove... |
| CVE-2026-45829 | CRITICAL | 10 | 12.4% | May 18, 2026 | A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un... |
| CVE-2026-41948 | CRITICAL | 9.4 | 0.5% | May 18, 2026 | Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate reque... |
| CVE-2026-41947 | CRITICAL | 9.3 | 0.5% | May 18, 2026 | Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set ... |
| CVE-2026-7304 | CRITICAL | 9.8 | 0.6% | May 18, 2026 | SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-lo... |
| CVE-2026-7302 | CRITICAL | 9.1 | 0.4% | May 18, 2026 | SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta... |
| CVE-2026-7301 | CRITICAL | 9.8 | 0.4% | May 18, 2026 | SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that cal... |
| CVE-2026-4320 | CRITICAL | 9.3 | 0.3% | May 18, 2026 | Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to pr... |
| CVE-2026-8721 | CRITICAL | 9.8 | 0.4% | May 17, 2026 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLs. Password parameters in P... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now