2026 CVE Vulnerabilities
45,029 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7414 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials ar... |
| CVE-2026-7413 | CRITICAL | 9.8 | 0.6% | May 7, 2026 | A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen... |
| CVE-2026-7821 | CRITICAL | 9.1 | 0.5% | May 7, 2026 | Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen... |
| CVE-2026-5788 | CRITICAL | 9.8 | 0.8% | May 7, 2026 | An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat... |
| CVE-2026-5787 | CRITICAL | 9.1 | 0.7% | May 7, 2026 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut... |
| CVE-2026-36458 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated i... |
| CVE-2026-6795 | CRITICAL | 9.6 | 0.2% | May 7, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive... |
| CVE-2026-41589 | CRITICAL | 9.6 | 0.4% | May 7, 2026 | Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP... |
| CVE-2026-30496 | CRITICAL | 9.8 | 0.3% | May 7, 2026 | The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that... |
| CVE-2026-8094 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2. |
| CVE-2026-8091 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thund... |
| CVE-2026-6508 | CRITICAL | 9.8 | 0.2% | May 7, 2026 | Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Acces... |
| CVE-2026-42010 | CRITICAL | 9.8 | 1.1% | May 7, 2026 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched ... |
| CVE-2026-33587 | CRITICAL | 10 | 0.2% | May 7, 2026 | Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subseque... |
| CVE-2026-41586 | CRITICAL | 9.3 | 0.4% | May 7, 2026 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applica... |
| CVE-2026-44603 | CRITICAL | 9.1 | 0.3% | May 7, 2026 | Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. |
| CVE-2026-42217 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-42216 | CRITICAL | 9.1 | 0.4% | May 7, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-41203 | CRITICAL | 9.4 | 0.5% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41202 | CRITICAL | 9.4 | 0.5% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41201 | CRITICAL | 9.1 | 0.3% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-40982 | CRITICAL | 9.1 | 0.7% | May 7, 2026 | Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server ... |
| CVE-2026-44597 | CRITICAL | 9.1 | 0.4% | May 7, 2026 | Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload,... |
| CVE-2026-40281 | CRITICAL | 9.1 | 0.6% | May 6, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint v... |
| CVE-2026-44112 | CRITICAL | 9.6 | 2.4% | May 6, 2026 | OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes tha... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now