2026 CVE Vulnerabilities
62,186 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46376 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access... |
| CVE-2026-46337 | MEDIUM | 5.3 | 0.5% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary... |
| CVE-2026-45731 | MEDIUM | 4.9 | 0.5% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relat... |
| CVE-2026-45707 | HIGH | 8.1 | 0.2% | May 29, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-45620 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or... |
| CVE-2026-45619 | MEDIUM | 6.5 | 0.1% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and o... |
| CVE-2026-45615 | HIGH | 8.2 | 0.2% | May 29, 2026 | mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod... |
| CVE-2026-45610 | MEDIUM | 6.5 | 0.1% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o... |
| CVE-2026-45582 | MEDIUM | 6.5 | 0.3% | May 29, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-45580 | MEDIUM | 5.4 | 0.1% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability.... |
| CVE-2026-45578 | HIGH | 8.8 | 0.3% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The... |
| CVE-2026-45555 | HIGH | 7.8 | 0.1% | May 29, 2026 | Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.... |
| CVE-2026-44698 | HIGH | 8.3 | 0.1% | May 29, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for ... |
| CVE-2026-44239 | HIGH | 8.8 | 0.3% | May 29, 2026 | FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes P... |
| CVE-2026-44238 | HIGH | 8.8 | 0.3% | May 29, 2026 | FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through... |
| CVE-2026-44237 | HIGH | 8.1 | 0.2% | May 29, 2026 | FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently ... |
| CVE-2026-40528 | HIGH | 7.8 | 0.1% | May 29, 2026 | OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_valu... |
| CVE-2026-40510 | MEDIUM | 6.8 | 0.2% | May 29, 2026 | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history... |
| CVE-2026-10075 | MEDIUM | 6.9 | 0.4% | May 29, 2026 | DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read ... |
| CVE-2026-10074 | MEDIUM | 6.9 | 0.3% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo... |
| CVE-2026-10073 | HIGH | 8.7 | 0.4% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to ... |
| CVE-2026-10072 | HIGH | 8.6 | 0.5% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up... |
| CVE-2026-10061 | CRITICAL | 9.8 | 5.0% | May 29, 2026 | A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. ... |
| CVE-2026-10060 | CRITICAL | 9.8 | 5.0% | May 29, 2026 | A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /gofor... |
| CVE-2026-9509 | HIGH | 8.7 | 0.4% | May 29, 2026 | An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now