2026 CVE Vulnerabilities
45,004 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25787 | CRITICAL | 9.3 | 0.4% | May 12, 2026 | Affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagn... |
| CVE-2026-25786 | CRITICAL | 9.3 | 0.4% | May 12, 2026 | Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page ... |
| CVE-2026-22924 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly... |
| CVE-2026-41872 | CRITICAL | 9.1 | 0.2% | May 12, 2026 | "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle at... |
| CVE-2026-34263 | CRITICAL | 9.6 | 0.6% | May 12, 2026 | Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious in... |
| CVE-2026-34260 | CRITICAL | 9.6 | 0.5% | May 12, 2026 | SAP S/4HANA (SAP Enterprise Search for ABAP) contains a SQL injection vulnerability that allows an authenticated attacke... |
| CVE-2026-45321 | CRITICAL | 9.6 | 2.3% | May 12, 2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were publ... |
| CVE-2026-43914 | CRITICAL | 9.8 | 0.3% | May 11, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaul... |
| CVE-2026-43900 | CRITICAL | 9.3 | 0.3% | May 11, 2026 | DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.... |
| CVE-2026-43899 | CRITICAL | 9.6 | 0.3% | May 11, 2026 | DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.... |
| CVE-2026-42882 | CRITICAL | 9.4 | 0.6% | May 11, 2026 | oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused ... |
| CVE-2026-42869 | CRITICAL | 10 | 0.4% | May 11, 2026 | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,... |
| CVE-2026-42864 | CRITICAL | 9.9 | 0.3% | May 11, 2026 | FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint ... |
| CVE-2026-8305 | CRITICAL | 9.8 | 0.6% | May 11, 2026 | A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookR... |
| CVE-2026-43995 | CRITICAL | 9.8 | 0.4% | May 11, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool i... |
| CVE-2026-43639 | CRITICAL | 9.1 | 0.6% | May 11, 2026 | Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user t... |
| CVE-2026-42858 | CRITICAL | 9.9 | 0.4% | May 11, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in... |
| CVE-2026-38567 | CRITICAL | 9.8 | 0.5% | May 11, 2026 | HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated di... |
| CVE-2026-7813 | CRITICAL | 9.9 | 0.5% | May 11, 2026 | Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Proces... |
| CVE-2026-44643 | CRITICAL | 10 | 0.5% | May 11, 2026 | Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an att... |
| CVE-2026-42613 | CRITICAL | 9.4 | 0.9% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attac... |
| CVE-2026-42608 | CRITICAL | 9.1 | 0.5% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash c... |
| CVE-2026-42607 | CRITICAL | 9.1 | 3.9% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achie... |
| CVE-2026-35157 | CRITICAL | 9.8 | 0.3% | May 11, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutraliz... |
| CVE-2026-8263 | CRITICAL | 9.8 | 4.6% | May 11, 2026 | A security flaw has been discovered in Tenda AC6 15.03.06.49_multi_TDE01. Affected is the function fromSetWirelessRepeat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now