2026 CVE Vulnerabilities
45,006 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44497 | CRITICAL | 9.1 | 0.2% | May 8, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, t... |
| CVE-2026-43465 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: RX, Fix XDP multi-buf frag counting for ... |
| CVE-2026-43414 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Completely fix fcport double free I... |
| CVE-2026-43407 | CRITICAL | 9.1 | 0.5% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph... |
| CVE-2026-43406 | CRITICAL | 9.1 | 0.5% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: prevent potential out-of-bounds reads in p... |
| CVE-2026-43402 | CRITICAL | 9.8 | 0.5% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: kthread: consolidate kthread exit paths to prevent ... |
| CVE-2026-43384 | CRITICAL | 9.8 | 0.5% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time ... |
| CVE-2026-43383 | CRITICAL | 9.4 | 0.4% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/tcp-md5: Fix MAC comparison to be constant-time... |
| CVE-2026-43379 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in smb_lazy_parent_lease_... |
| CVE-2026-43376 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free by using call_rcu() for o... |
| CVE-2026-41583 | CRITICAL | 9.1 | 0.3% | May 8, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, a... |
| CVE-2026-41574 | CRITICAL | 9.8 | 0.8% | May 8, 2026 | Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incomin... |
| CVE-2026-37431 | CRITICAL | 9.8 | 0.3% | May 8, 2026 | Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber paramete... |
| CVE-2026-44336 | CRITICAL | 9.6 | 0.6% | May 8, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (prais... |
| CVE-2026-44335 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw... |
| CVE-2026-44128 | CRITICAL | 9.3 | 0.8% | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI be... |
| CVE-2026-44126 | CRITICAL | 9.2 | 0.5% | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from th... |
| CVE-2026-44125 | CRITICAL | 9.3 | 0.4% | May 8, 2026 | SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the ... |
| CVE-2026-43341 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/ipv6: ioam6: prevent schema length wraparound i... |
| CVE-2026-43304 | CRITICAL | 9.8 | 0.5% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: libceph: define and enforce CEPH_MAX_KEY_LEN When ... |
| CVE-2026-41512 | CRITICAL | 9.9 | 0.6% | May 8, 2026 | ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a r... |
| CVE-2026-41509 | CRITICAL | 9.8 | 0.3% | May 8, 2026 | CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Pri... |
| CVE-2026-41507 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.p... |
| CVE-2026-41497 | CRITICAL | 9.8 | 0.5% | May 8, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not a... |
| CVE-2026-25199 | CRITICAL | 9.1 | 0.5% | May 8, 2026 | Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now