2026 CVE Vulnerabilities
44,992 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8507 | CRITICAL | 9.8 | 0.6% | May 17, 2026 | Crypt::OpenSSL::PKCS12 versions through 1.94 for Perl have out-of-bounds (OOB) write flaws. When parsing a PKCS12 file,... |
| CVE-2026-8757 | CRITICAL | 9.1 | 0.6% | May 17, 2026 | A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/fram... |
| CVE-2026-8751 | CRITICAL | 9.8 | 0.4% | May 17, 2026 | A security flaw has been discovered in h2oai h2o-3 up to 7402. This affects the function importBinaryModel of the file h... |
| CVE-2026-44566 | CRITICAL | 9.8 | 0.3% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, whe... |
| CVE-2026-8696 | CRITICAL | 9.8 | 0.6% | May 15, 2026 | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that a... |
| CVE-2026-44551 | CRITICAL | 9.1 | 1.5% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the L... |
| CVE-2026-8686 | CRITICAL | 9.1 | 0.4% | May 15, 2026 | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a den... |
| CVE-2026-46364 | CRITICAL | 9.8 | 1.7% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and ... |
| CVE-2026-45010 | CRITICAL | 9.3 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/... |
| CVE-2026-8695 | CRITICAL | 9.8 | 0.6% | May 15, 2026 | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers t... |
| CVE-2026-44774 | CRITICAL | 9.9 | 0.5% | May 15, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP... |
| CVE-2026-44717 | CRITICAL | 9.8 | 0.5% | May 15, 2026 | MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the ... |
| CVE-2026-44699 | CRITICAL | 9.1 | 0.2% | May 15, 2026 | LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parame... |
| CVE-2026-42155 | CRITICAL | 9.3 | 0.3% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-41258 | CRITICAL | 9.1 | 0.3% | May 15, 2026 | OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptRe... |
| CVE-2026-45772 | CRITICAL | 9.8 | 0.4% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turbo... |
| CVE-2026-2031 | CRITICAL | 10 | 0.5% | May 15, 2026 | An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prio... |
| CVE-2026-7182 | CRITICAL | 9.2 | 0.4% | May 15, 2026 | Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenti... |
| CVE-2026-41553 | CRITICAL | 10 | 0.6% | May 15, 2026 | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "d... |
| CVE-2026-8398 | CRITICAL | 9.8 | 1.4% | May 15, 2026 | A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 ... |
| CVE-2026-5229 | CRITICAL | 9.8 | 0.7% | May 15, 2026 | The Form Notify plugin for WordPress is vulnerable to Authentication Bypass in versions up to and including 1.1.10. This... |
| CVE-2026-0481 | CRITICAL | 9.2 | 0.3% | May 15, 2026 | Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to per... |
| CVE-2026-44666 | CRITICAL | 9.3 | 0.3% | May 14, 2026 | HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeStri... |
| CVE-2026-44212 | CRITICAL | 9.3 | 0.3% | May 14, 2026 | PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scriptin... |
| CVE-2026-8634 | CRITICAL | 9.3 | 0.7% | May 14, 2026 | Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now