2026 CVE Vulnerabilities
44,996 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44442 | CRITICAL | 9.9 | 0.3% | May 13, 2026 | ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforc... |
| CVE-2026-44194 | CRITICAL | 9.1 | 6.4% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE)... |
| CVE-2026-44193 | CRITICAL | 9.1 | 0.7% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_se... |
| CVE-2026-45714 | CRITICAL | 9.1 | 0.4% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne... |
| CVE-2026-45053 | CRITICAL | 9.1 | 0.6% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists ... |
| CVE-2026-44377 | CRITICAL | 9.1 | 0.7% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne... |
| CVE-2026-44364 | CRITICAL | 9.3 | 0.2% | May 13, 2026 | MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site... |
| CVE-2026-44351 | CRITICAL | 9.1 | 0.2% | May 13, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerabili... |
| CVE-2026-42584 | CRITICAL | 9.1 | 0.8% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClien... |
| CVE-2026-42581 | CRITICAL | 9.8 | 0.6% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjec... |
| CVE-2026-42579 | CRITICAL | 9.1 | 1.0% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's D... |
| CVE-2026-42032 | CRITICAL | 9.1 | 0.4% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
| CVE-2026-42031 | CRITICAL | 9.8 | 1.8% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
| CVE-2026-0258 | CRITICAL | 9.1 | 0.3% | May 13, 2026 | A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software al... |
| CVE-2026-0257 | CRITICAL | 9.1 | 86.7% | May 13, 2026 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software all... |
| CVE-2026-45411 | CRITICAL | 9.8 | 0.6% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield*... |
| CVE-2026-44009 | CRITICAL | 9.8 | 0.8% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2. |
| CVE-2026-44008 | CRITICAL | 9.8 | 0.9% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with obj... |
| CVE-2026-44007 | CRITICAL | 9.1 | 0.9% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code... |
| CVE-2026-44006 | CRITICAL | 10 | 0.8% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which... |
| CVE-2026-44005 | CRITICAL | 10 | 0.8% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-r... |
| CVE-2026-43999 | CRITICAL | 9.9 | 1.0% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the modul... |
| CVE-2026-43997 | CRITICAL | 10 | 1.0% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are vario... |
| CVE-2026-0264 | CRITICAL | 9.8 | 0.4% | May 13, 2026 | A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows a... |
| CVE-2026-0263 | CRITICAL | 9.8 | 0.3% | May 13, 2026 | A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now