2026 CVE Vulnerabilities
62,178 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45352 | HIGH | 7.5 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i... |
| CVE-2026-45324 | LOW | 3.3 | 0.1% | May 29, 2026 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm... |
| CVE-2026-45294 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset ... |
| CVE-2026-45151 | LOW | 2.9 | 0.2% | May 29, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can derefe... |
| CVE-2026-45149 | HIGH | 7.5 | 0.3% | May 29, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.... |
| CVE-2026-44640 | MEDIUM | 4.5 | 0.1% | May 29, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_... |
| CVE-2026-44422 | HIGH | 8.8 | 0.4% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts on... |
| CVE-2026-44421 | HIGH | 8.8 | 0.5% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a h... |
| CVE-2026-44420 | HIGH | 8.8 | 3.7% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a h... |
| CVE-2026-44287 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/... |
| CVE-2026-44285 | HIGH | 7.7 | 0.3% | May 29, 2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo... |
| CVE-2026-42500 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid ... |
| CVE-2026-34127 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG... |
| CVE-2026-9051 | CRITICAL | 9.3 | 0.6% | May 29, 2026 | There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an ... |
| CVE-2026-49386 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles ... |
| CVE-2026-49385 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service account... |
| CVE-2026-49384 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible |
| CVE-2026-49383 | LOW | 3.3 | 0.1% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible |
| CVE-2026-49382 | HIGH | 7.8 | 0.1% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin |
| CVE-2026-49381 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
| CVE-2026-49380 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
| CVE-2026-49379 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
| CVE-2026-49378 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
| CVE-2026-49377 | MEDIUM | 4.3 | 0.7% | May 29, 2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
| CVE-2026-49376 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now