2026 CVE Vulnerabilities
62,176 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7459 | HIGH | 7.5 | 0.6% | May 30, 2026 | The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscr... |
| CVE-2026-10113 | MEDIUM | 4.3 | 0.3% | May 30, 2026 | A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the libr... |
| CVE-2026-5071 | HIGH | 7.8 | 0.2% | May 30, 2026 | The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using on... |
| CVE-2026-10112 | LOW | 2.4 | 0.2% | May 30, 2026 | A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the compon... |
| CVE-2026-10111 | HIGH | 7.3 | 0.3% | May 30, 2026 | A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Logi... |
| CVE-2026-10110 | HIGH | 7.3 | 0.3% | May 30, 2026 | A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of... |
| CVE-2026-48840 | MEDIUM | 5.3 | 0.3% | May 30, 2026 | Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of unini... |
| CVE-2026-9831 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-c... |
| CVE-2026-4387 | LOW | 2 | 0.1% | May 29, 2026 | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication s... |
| CVE-2026-48811 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a ... |
| CVE-2026-48810 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating... |
| CVE-2026-48557 | HIGH | 8.8 | 0.4% | May 29, 2026 | Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanit... |
| CVE-2026-48555 | HIGH | 7.4 | 0.2% | May 29, 2026 | Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows rem... |
| CVE-2026-47266 | HIGH | 8.7 | 0.3% | May 29, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing... |
| CVE-2026-47123 | HIGH | 7.5 | 0.1% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processin... |
| CVE-2026-46599 | HIGH | 7.5 | 0.4% | May 29, 2026 | The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit... |
| CVE-2026-46527 | HIGH | 7.5 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has c... |
| CVE-2026-46385 | HIGH | 7.5 | 0.6% | May 29, 2026 | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-contro... |
| CVE-2026-46384 | HIGH | 7.5 | 0.5% | May 29, 2026 | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit val... |
| CVE-2026-45700 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an... |
| CVE-2026-45697 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted ... |
| CVE-2026-45613 | LOW | 3.3 | 0.1% | May 29, 2026 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bi... |
| CVE-2026-45372 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's se... |
| CVE-2026-45352 | HIGH | 7.5 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i... |
| CVE-2026-45324 | LOW | 3.3 | 0.1% | May 29, 2026 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now