2026 CVE Vulnerabilities
44,992 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8580 | CRITICAL | 9.6 | 0.2% | May 14, 2026 | Use after free in Mojo in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-8511 | CRITICAL | 9.6 | 0.2% | May 14, 2026 | Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox... |
| CVE-2026-26191 | CRITICAL | 9.8 | 0.8% | May 14, 2026 | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer ... |
| CVE-2026-45375 | CRITICAL | 9 | 0.4% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) r... |
| CVE-2026-44670 | CRITICAL | 9.4 | 0.5% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / da... |
| CVE-2026-44592 | CRITICAL | 9.4 | 0.2% | May 14, 2026 | Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the N... |
| CVE-2026-44588 | CRITICAL | 9.4 | 0.5% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/... |
| CVE-2026-44523 | CRITICAL | 10 | 0.1% | May 14, 2026 | Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JW... |
| CVE-2026-41315 | CRITICAL | 9.8 | 1.0% | May 14, 2026 | mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command ex... |
| CVE-2026-46470 | CRITICAL | 9.1 | 0.2% | May 14, 2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's ... |
| CVE-2026-44542 | CRITICAL | 9.1 | 0.5% | May 14, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-contr... |
| CVE-2026-42555 | CRITICAL | 9.1 | 0.6% | May 14, 2026 | Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32... |
| CVE-2026-20182 | CRITICAL | 10 | 87.7% | May 14, 2026 | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fi... |
| CVE-2026-42596 | CRITICAL | 9.4 | 0.4% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's d... |
| CVE-2026-42589 | CRITICAL | 9.8 | 2.9% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write... |
| CVE-2026-44484 | CRITICAL | 9.8 | 0.4% | May 14, 2026 | PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu... |
| CVE-2026-44482 | CRITICAL | 9.6 | 0.3% | May 14, 2026 | soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8... |
| CVE-2026-42457 | CRITICAL | 9 | 0.3% | May 14, 2026 | vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio... |
| CVE-2026-2347 | CRITICAL | 9.8 | 0.4% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Comme... |
| CVE-2026-6512 | CRITICAL | 9.1 | 0.3% | May 14, 2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.... |
| CVE-2026-6510 | CRITICAL | 9.8 | 0.4% | May 14, 2026 | The InfusedWoo Pro plugin for WordPress is vulnerable to privilege escalation via missing authorization in all versions ... |
| CVE-2026-6271 | CRITICAL | 9.8 | 0.7% | May 14, 2026 | The Career Section plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7... |
| CVE-2026-8181 | CRITICAL | 9.8 | 14.6% | May 14, 2026 | The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulne... |
| CVE-2026-8500 | CRITICAL | 9.8 | 1.7% | May 13, 2026 | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing ht... |
| CVE-2026-45158 | CRITICAL | 9.1 | 0.5% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now