2026 CVE Vulnerabilities
44,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42945 | CRITICAL | 9.2 | 66.0% | May 13, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w... |
| CVE-2026-42557 | CRITICAL | 9.6 | 0.4% | May 13, 2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit... |
| CVE-2026-41225 | CRITICAL | 9.1 | 0.3% | May 13, 2026 | A vulnerability exists in iControl REST where a highly privileged, authenticated attacker with at least the Manager role... |
| CVE-2026-42062 | CRITICAL | 9.8 | 1.6% | May 13, 2026 | ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If process... |
| CVE-2026-40621 | CRITICAL | 9.8 | 0.5% | May 13, 2026 | ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected produc... |
| CVE-2026-41050 | CRITICAL | 9.9 | 0.4% | May 13, 2026 | Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git pus... |
| CVE-2026-32661 | CRITICAL | 9.8 | 0.5% | May 13, 2026 | Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS ve... |
| CVE-2026-44547 | CRITICAL | 9.6 | 0.2% | May 12, 2026 | ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The ... |
| CVE-2026-42288 | CRITICAL | 10 | 0.6% | May 12, 2026 | ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-... |
| CVE-2026-41901 | CRITICAL | 9 | 0.4% | May 12, 2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security ... |
| CVE-2026-44262 | CRITICAL | 9.4 | 5.9% | May 12, 2026 | Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints ar... |
| CVE-2026-44258 | CRITICAL | 9.3 | 0.3% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targe... |
| CVE-2026-44257 | CRITICAL | 9.3 | 0.3% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk usin... |
| CVE-2026-44015 | CRITICAL | 9.9 | 0.3% | May 12, 2026 | Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Serve... |
| CVE-2026-43948 | CRITICAL | 9.9 | 0.4% | May 12, 2026 | wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_... |
| CVE-2026-42854 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr... |
| CVE-2026-42196 | CRITICAL | 9.9 | 0.6% | May 12, 2026 | django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerabl... |
| CVE-2026-45185 | CRITICAL | 9.8 | 1.2% | May 12, 2026 | Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p... |
| CVE-2026-44225 | CRITICAL | 9.3 | 0.4% | May 12, 2026 | Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.... |
| CVE-2026-44221 | CRITICAL | 9 | 0.3% | May 12, 2026 | ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tok... |
| CVE-2026-42889 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypa... |
| CVE-2026-8431 | CRITICAL | 9.4 | 0.4% | May 12, 2026 | An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggeri... |
| CVE-2026-8430 | CRITICAL | 9.2 | 0.4% | May 12, 2026 | SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certa... |
| CVE-2026-34660 | CRITICAL | 9.3 | 0.4% | May 12, 2026 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by an Incorrect Authorization vulnerability that c... |
| CVE-2026-34659 | CRITICAL | 9.6 | 0.6% | May 12, 2026 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now