2026 CVE Vulnerabilities
45,065 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42222 | CRITICAL | 9.8 | 0.3% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exist... |
| CVE-2026-42221 | CRITICAL | 9.8 | 0.3% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticate... |
| CVE-2026-41926 | CRITICAL | 9.3 | 1.2% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cg... |
| CVE-2026-41925 | CRITICAL | 9.3 | 3.4% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi bin... |
| CVE-2026-41924 | CRITICAL | 9.3 | 2.7% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest... |
| CVE-2026-41923 | CRITICAL | 9.3 | 2.6% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cg... |
| CVE-2026-41922 | CRITICAL | 9.3 | 5.0% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cg... |
| CVE-2026-42235 | CRITICAL | 9.6 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated a... |
| CVE-2026-42233 | CRITICAL | 9.8 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle... |
| CVE-2026-42796 | CRITICAL | 9.8 | 0.7% | May 4, 2026 | Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoi... |
| CVE-2026-42087 | CRITICAL | 9.6 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-41571 | CRITICAL | 9.4 | 0.3% | May 4, 2026 | Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls ba... |
| CVE-2026-42812 | CRITICAL | 9.9 | 0.4% | May 4, 2026 | In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table ... |
| CVE-2026-42811 | CRITICAL | 9.9 | 0.4% | May 4, 2026 | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, bu... |
| CVE-2026-42810 | CRITICAL | 9.9 | 0.4% | May 4, 2026 | Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access pol... |
| CVE-2026-42809 | CRITICAL | 9.9 | 0.4% | May 4, 2026 | Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effectiv... |
| CVE-2026-42376 | CRITICAL | 9.8 | 0.5% | May 4, 2026 | D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet... |
| CVE-2026-42090 | CRITICAL | 9.6 | 0.5% | May 4, 2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and ... |
| CVE-2026-42076 | CRITICAL | 9.8 | 1.3% | May 4, 2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability ... |
| CVE-2026-42027 | CRITICAL | 9.8 | 0.7% | May 4, 2026 | Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5,... |
| CVE-2026-40682 | CRITICAL | 9.1 | 0.5% | May 4, 2026 | XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affec... |
| CVE-2026-26956 | CRITICAL | 9.8 | 0.9% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary... |
| CVE-2026-26332 | CRITICAL | 10 | 0.7% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sa... |
| CVE-2026-25293 | CRITICAL | 9.8 | 0.2% | May 4, 2026 | Buffer overflow due to incorrect authorization in PLC FW |
| CVE-2026-24781 | CRITICAL | 9.8 | 1.2% | May 4, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now