2026 CVE Vulnerabilities
45,029 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41507 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.p... |
| CVE-2026-41497 | CRITICAL | 9.8 | 0.5% | May 8, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not a... |
| CVE-2026-25199 | CRITICAL | 9.1 | 0.5% | May 8, 2026 | Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This... |
| CVE-2026-8153 | CRITICAL | 9.8 | 1.8% | May 8, 2026 | OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthe... |
| CVE-2026-8076 | CRITICAL | 9.3 | 0.3% | May 8, 2026 | Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of nu... |
| CVE-2026-6213 | CRITICAL | 10 | 0.3% | May 8, 2026 | A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an... |
| CVE-2026-43944 | CRITICAL | 9.6 | 0.4% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before ... |
| CVE-2026-43941 | CRITICAL | 9.6 | 0.4% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, ... |
| CVE-2026-42264 | CRITICAL | 9.1 | 0.7% | May 8, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive con... |
| CVE-2026-42208 | CRITICAL | 9.8 | 86.6% | May 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before ver... |
| CVE-2026-41900 | CRITICAL | 10 | 0.9% | May 8, 2026 | OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec... |
| CVE-2026-41501 | CRITICAL | 9.8 | 1.3% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a comm... |
| CVE-2026-41500 | CRITICAL | 9.8 | 1.6% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a comm... |
| CVE-2026-42880 | CRITICAL | 9.6 | 0.5% | May 7, 2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0... |
| CVE-2026-8034 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that a... |
| CVE-2026-7891 | CRITICAL | 9.1 | 0.3% | May 7, 2026 | A vulnerability has been identified in Mendix Runtime (All versions). Mendix documentation for access rules does not ade... |
| CVE-2026-35435 | CRITICAL | 10 | 1.2% | May 7, 2026 | Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges ... |
| CVE-2026-35428 | CRITICAL | 9.6 | 0.9% | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unaut... |
| CVE-2026-33844 | CRITICAL | 9 | 1.0% | May 7, 2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove... |
| CVE-2026-33109 | CRITICAL | 9.9 | 0.7% | May 7, 2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove... |
| CVE-2026-41691 | CRITICAL | 9.1 | 0.3% | May 7, 2026 | Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internat... |
| CVE-2026-42284 | CRITICAL | 9.8 | 0.6% | May 7, 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_... |
| CVE-2026-41902 | CRITICAL | 9.1 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-s... |
| CVE-2026-37709 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958... |
| CVE-2026-7415 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now