2026 CVE Vulnerabilities
63,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45149 | HIGH | 7.5 | 0.3% | May 29, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.... |
| CVE-2026-44640 | MEDIUM | 4.5 | 0.1% | May 29, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_... |
| CVE-2026-44422 | HIGH | 8.8 | 0.4% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts on... |
| CVE-2026-44421 | HIGH | 8.8 | 0.5% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a h... |
| CVE-2026-44420 | HIGH | 8.8 | 3.7% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a h... |
| CVE-2026-44287 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/... |
| CVE-2026-44285 | HIGH | 7.7 | 0.3% | May 29, 2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo... |
| CVE-2026-42500 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid ... |
| CVE-2026-34127 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG... |
| CVE-2026-9051 | CRITICAL | 9.3 | 0.6% | May 29, 2026 | There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an ... |
| CVE-2026-49386 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles ... |
| CVE-2026-49385 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service account... |
| CVE-2026-49384 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible |
| CVE-2026-49383 | LOW | 3.3 | 0.1% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible |
| CVE-2026-49382 | HIGH | 7.8 | 0.1% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin |
| CVE-2026-49381 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
| CVE-2026-49380 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
| CVE-2026-49379 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
| CVE-2026-49378 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
| CVE-2026-49377 | MEDIUM | 4.3 | 0.7% | May 29, 2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
| CVE-2026-49376 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
| CVE-2026-49375 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page |
| CVE-2026-49374 | HIGH | 7.6 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters |
| CVE-2026-49373 | HIGH | 8.8 | 0.4% | May 29, 2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings |
| CVE-2026-49372 | HIGH | 7.5 | 0.3% | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now