2026 CVE Vulnerabilities
45,065 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40330 | CRITICAL | 9.3 | 0.4% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu... |
| CVE-2026-40329 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exist... |
| CVE-2026-34084 | CRITICAL | 9.8 | 0.7% | May 5, 2026 | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1... |
| CVE-2026-7854 | CRITICAL | 9.8 | 5.9% | May 5, 2026 | A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function ... |
| CVE-2026-38428 | CRITICAL | 9.8 | 0.4% | May 5, 2026 | Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a G... |
| CVE-2026-27960 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 t... |
| CVE-2026-7853 | CRITICAL | 9.8 | 1.5% | May 5, 2026 | A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.a... |
| CVE-2026-38431 | CRITICAL | 9.8 | 0.4% | May 5, 2026 | ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to crea... |
| CVE-2026-38429 | CRITICAL | 9.8 | 0.3% | May 5, 2026 | OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML par... |
| CVE-2026-7411 | CRITICAL | 10 | 3.7% | May 5, 2026 | In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTT... |
| CVE-2026-43071 | CRITICAL | 9.1 | 0.4% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: dcache: Limit the minimal number of bucket to two ... |
| CVE-2026-43067 | CRITICAL | 9.8 | 0.4% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: handle wraparound when searching for blocks f... |
| CVE-2026-34002 | CRITICAL | 9.1 | 0.5% | May 5, 2026 | A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension... |
| CVE-2026-34000 | CRITICAL | 9.1 | 0.5% | May 5, 2026 | A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifical... |
| CVE-2026-7834 | CRITICAL | 9.8 | 0.6% | May 5, 2026 | A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_white... |
| CVE-2026-36356 | CRITICAL | 9.1 | 14.4% | May 5, 2026 | The GoAhead web server on MeiG Smart FORGE_SLT711 devices (firmware MDM9607.LE.1.0-00110-STD.PROD-1) allows unauthentica... |
| CVE-2026-34408 | CRITICAL | 9.1 | 0.3% | May 5, 2026 | An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset f... |
| CVE-2026-43566 | CRITICAL | 9.8 | 0.4% | May 5, 2026 | OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade... |
| CVE-2026-43534 | CRITICAL | 9.8 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued a... |
| CVE-2026-43526 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that al... |
| CVE-2026-40797 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC We... |
| CVE-2026-7823 | CRITICAL | 9.8 | 1.8% | May 5, 2026 | A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of... |
| CVE-2026-5294 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This ... |
| CVE-2026-5722 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.... |
| CVE-2026-42238 | CRITICAL | 9.8 | 0.8% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore end... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now