2026 CVE Vulnerabilities
63,747 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24444 | CRITICAL | 9.8 | 0.5% | May 28, 2026 | SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability ... |
| CVE-2026-48735 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr... |
| CVE-2026-48526 | HIGH | 7.4 | 0.4% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil... |
| CVE-2026-48525 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u... |
| CVE-2026-48524 | LOW | 3.7 | 0.2% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP r... |
| CVE-2026-48523 | MEDIUM | 5.4 | 0.1% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list ... |
| CVE-2026-48522 | MEDIUM | 4.2 | 0.2% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to url... |
| CVE-2026-48156 | LOW | 3.3 | 0.1% | May 28, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr... |
| CVE-2026-48155 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr... |
| CVE-2026-47762 | MEDIUM | 5.4 | 0.2% | May 28, 2026 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via f... |
| CVE-2026-47761 | MEDIUM | 5.4 | 0.2% | May 28, 2026 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in th... |
| CVE-2026-47760 | MEDIUM | 5.4 | 0.2% | May 28, 2026 | TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by ... |
| CVE-2026-47759 | MEDIUM | 5.4 | 0.2% | May 28, 2026 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via u... |
| CVE-2026-45017 | HIGH | 7.5 | 0.3% | May 28, 2026 | Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and Cac... |
| CVE-2026-44672 | CRITICAL | 9.3 | 0.3% | May 28, 2026 | mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30... |
| CVE-2026-44594 | HIGH | 7.5 | 0.3% | May 28, 2026 | esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI... |
| CVE-2026-44593 | HIGH | 8.7 | 0.4% | May 28, 2026 | esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first ret... |
| CVE-2026-44358 | HIGH | 8.2 | 0.2% | May 28, 2026 | Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior t... |
| CVE-2026-41565 | HIGH | 7.5 | 0.5% | May 28, 2026 | CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_dec... |
| CVE-2026-35676 | HIGH | 8.8 | 0.2% | May 28, 2026 | phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint ... |
| CVE-2026-35675 | HIGH | 8.8 | 0.3% | May 28, 2026 | phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthe... |
| CVE-2026-35672 | HIGH | 8.7 | 0.4% | May 28, 2026 | phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientT... |
| CVE-2026-35671 | HIGH | 8.8 | 0.3% | May 28, 2026 | phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint... |
| CVE-2026-9828 | LOW | 2.9 | 0.4% | May 28, 2026 | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-... |
| CVE-2026-8990 | MEDIUM | 5.3 | 0.2% | May 28, 2026 | A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now