2026 CVE Vulnerabilities
63,153 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42941 | HIGH | 8.7 | 0.2% | May 29, 2026 | The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password c... |
| CVE-2026-42929 | HIGH | 8.7 | 0.2% | May 29, 2026 | Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. |
| CVE-2026-40425 | MEDIUM | 4.9 | 0.4% | May 29, 2026 | The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file... |
| CVE-2026-7786 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintex... |
| CVE-2026-6824 | HIGH | 8.4 | 0.4% | May 29, 2026 | A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitiza... |
| CVE-2026-5768 | HIGH | 8.8 | 0.3% | May 29, 2026 | The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing p... |
| CVE-2026-5386 | CRITICAL | 9.1 | 0.6% | May 29, 2026 | The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an ... |
| CVE-2026-47179 | HIGH | 7.7 | 0.3% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.Ge... |
| CVE-2026-47125 | HIGH | 8.8 | 0.2% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/envi... |
| CVE-2026-45668 | CRITICAL | 9.3 | 0.2% | May 29, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
| CVE-2026-45661 | CRITICAL | 9.9 | 0.7% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerab... |
| CVE-2026-45660 | MEDIUM | 5.4 | 0.2% | May 29, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image prox... |
| CVE-2026-45633 | CRITICAL | 9.9 | 0.9% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injecti... |
| CVE-2026-45632 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enfor... |
| CVE-2026-45631 | CRITICAL | 10 | 0.4% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SEC... |
| CVE-2026-45630 | CRITICAL | 9 | 0.8% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection... |
| CVE-2026-45629 | CRITICAL | 9.9 | 0.8% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection... |
| CVE-2026-45628 | CRITICAL | 9.6 | 0.2% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands ... |
| CVE-2026-45627 | HIGH | 8.2 | 0.2% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticat... |
| CVE-2026-45626 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /enviro... |
| CVE-2026-45625 | CRITICAL | 9.9 | 0.4% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-bas... |
| CVE-2026-45577 | MEDIUM | 6.9 | 0.2% | May 29, 2026 | Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public... |
| CVE-2026-44697 | HIGH | 8.6 | 0.4% | May 29, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-... |
| CVE-2026-43917 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware ... |
| CVE-2026-10108 | HIGH | 8.7 | 0.5% | May 29, 2026 | xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now