2026 CVE Vulnerabilities
45,006 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6104 | CRITICAL | 9.1 | 0.5% | May 10, 2026 | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is pas... |
| CVE-2026-7261 | CRITICAL | 9.8 | 0.3% | May 10, 2026 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer i... |
| CVE-2026-6722 | CRITICAL | 9.8 | 0.9% | May 10, 2026 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extensio... |
| CVE-2026-42601 | CRITICAL | 9.8 | 0.4% | May 9, 2026 | ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddVi... |
| CVE-2026-42571 | CRITICAL | 9 | 0.3% | May 9, 2026 | Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.2... |
| CVE-2026-42569 | CRITICAL | 9.4 | 1.2% | May 9, 2026 | phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS a... |
| CVE-2026-42257 | CRITICAL | 9.8 | 0.4% | May 9, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5... |
| CVE-2026-42560 | CRITICAL | 9.1 | 0.4% | May 9, 2026 | auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1... |
| CVE-2026-6665 | CRITICAL | 9.8 | 0.4% | May 9, 2026 | The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the conten... |
| CVE-2026-44313 | CRITICAL | 9.1 | 0.3% | May 9, 2026 | Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior... |
| CVE-2026-42556 | CRITICAL | 9 | 0.3% | May 8, 2026 | Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who c... |
| CVE-2026-42454 | CRITICAL | 9.9 | 0.7% | May 8, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-42354 | CRITICAL | 9.8 | 0.6% | May 8, 2026 | Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical v... |
| CVE-2026-42302 | CRITICAL | 9.8 | 0.7% | May 8, 2026 | FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of... |
| CVE-2026-42298 | CRITICAL | 9.8 | 0.5% | May 8, 2026 | Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Pu... |
| CVE-2026-42287 | CRITICAL | 10 | 0.2% | May 8, 2026 | Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and u... |
| CVE-2026-42193 | CRITICAL | 9.1 | 0.1% | May 8, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accep... |
| CVE-2026-44400 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile ... |
| CVE-2026-44694 | CRITICAL | 9.1 | 0.2% | May 8, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From ... |
| CVE-2026-42160 | CRITICAL | 10 | 0.2% | May 8, 2026 | Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F... |
| CVE-2026-8178 | CRITICAL | 9.2 | 0.6% | May 8, 2026 | An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load ... |
| CVE-2026-42072 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and wri... |
| CVE-2026-41889 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simp... |
| CVE-2026-38360 | CRITICAL | 9.8 | 6.0% | May 8, 2026 | Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut... |
| CVE-2026-41070 | CRITICAL | 10 | 0.4% | May 8, 2026 | openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (S... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now