2026 CVE Vulnerabilities
45,001 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34659 | CRITICAL | 9.6 | 0.6% | May 12, 2026 | Adobe Connect versions 2025.9.15, 2025.8.157 and earlier are affected by a Deserialization of Untrusted Data vulnerabili... |
| CVE-2026-44343 | CRITICAL | 9.8 | 0.4% | May 12, 2026 | WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard t... |
| CVE-2026-44277 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticat... |
| CVE-2026-44196 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication... |
| CVE-2026-44183 | CRITICAL | 9.8 | 0.2% | May 12, 2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c... |
| CVE-2026-42898 | CRITICAL | 9.9 | 1.2% | May 12, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a... |
| CVE-2026-42833 | CRITICAL | 9.1 | 0.7% | May 12, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a... |
| CVE-2026-42823 | CRITICAL | 9.9 | 0.6% | May 12, 2026 | Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-42300 | CRITICAL | 9.3 | 0.3% | May 12, 2026 | DevGuard provides vulnerability management for the full software supply chain. Prior to 1.2.2, the SessionMiddleware acc... |
| CVE-2026-42048 | CRITICAL | 9.6 | 4.4% | May 12, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to... |
| CVE-2026-41103 | CRITICAL | 9.1 | 5.4% | May 12, 2026 | Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unautho... |
| CVE-2026-41096 | CRITICAL | 9.8 | 1.9% | May 12, 2026 | Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network. |
| CVE-2026-41089 | CRITICAL | 9.8 | 72.3% | May 12, 2026 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. |
| CVE-2026-40402 | CRITICAL | 9.3 | 0.3% | May 12, 2026 | Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-33821 | CRITICAL | 9.9 | 0.7% | May 12, 2026 | Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privi... |
| CVE-2026-33117 | CRITICAL | 9.1 | 0.5% | May 12, 2026 | The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path... |
| CVE-2026-31242 | CRITICAL | 9.1 | 0.5% | May 12, 2026 | The mem0 v1.0.0 server lacks authentication and authorization controls for its memory reset functionality accessible via... |
| CVE-2026-31239 | CRITICAL | 9.8 | 0.4% | May 12, 2026 | The mamba language model framework thru 2.2.6 is vulnerable to insecure deserialization (CWE-502) when loading pre-train... |
| CVE-2026-31238 | CRITICAL | 9.8 | 0.5% | May 12, 2026 | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) in its model serving component. Whe... |
| CVE-2026-31237 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | The Ludwig framework thru 0.10.4 is vulnerable to insecure deserialization (CWE-502) through its predict() method. When ... |
| CVE-2026-31236 | CRITICAL | 9.8 | 0.3% | May 12, 2026 | The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument.... |
| CVE-2026-31235 | CRITICAL | 9.8 | 0.5% | May 12, 2026 | The imgaug library thru 0.4.0 contains an insecure deserialization vulnerability in its BackgroundAugmenter class within... |
| CVE-2026-31234 | CRITICAL | 9.8 | 0.7% | May 12, 2026 | Horovod thru 0.28.1 contains an insecure deserialization vulnerability (CWE-502) in its KVStore HTTP server component. T... |
| CVE-2026-31233 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. Whe... |
| CVE-2026-31231 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now