2026 CVE Vulnerabilities
63,747 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8980 | CRITICAL | 9.3 | 0.3% | May 28, 2026 | The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-priv... |
| CVE-2026-8979 | CRITICAL | 9.3 | 0.6% | May 28, 2026 | The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated re... |
| CVE-2026-49238 | HIGH | 8.4 | 0.5% | May 28, 2026 | An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server)... |
| CVE-2026-49237 | HIGH | 7.8 | 0.1% | May 28, 2026 | An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-519... |
| CVE-2026-42250 | MEDIUM | 4.8 | 0.1% | May 28, 2026 | bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the applicatio... |
| CVE-2026-37579 | HIGH | 7.3 | 0.3% | May 28, 2026 | An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMe... |
| CVE-2026-37266 | HIGH | 8 | 0.3% | May 28, 2026 | An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary ... |
| CVE-2026-9818 | — | — | — | May 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-9658 | HIGH | 7.3 | 0.2% | May 28, 2026 | Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. T... |
| CVE-2026-40914 | MEDIUM | 4.3 | 0.4% | May 28, 2026 | A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that ... |
| CVE-2026-9813 | CRITICAL | 9.9 | 0.2% | May 28, 2026 | FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL ... |
| CVE-2026-4377 | MEDIUM | 6 | 0.1% | May 28, 2026 | Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it... |
| CVE-2026-47074 | HIGH | 8.7 | 0.2% | May 28, 2026 | Improper Certificate Validation vulnerability in ex-aws ex_aws_sns (ExAws.SNS, ExAws.SNS.PublicKeyCache modules) allows ... |
| CVE-2026-46241 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: fix use-after-free on registration fa... |
| CVE-2026-46240 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: iris: Fix use-after-free in iris_release_int... |
| CVE-2026-46239 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov5647: Fix runtime PM refcount leak in... |
| CVE-2026-46238 | HIGH | 8.8 | 0.3% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: stop caching unowned originator pointer... |
| CVE-2026-46237 | — | — | — | May 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-46236 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: rc: xbox_remote: heed DMA restrictions The ... |
| CVE-2026-46235 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: saa7164: add ioremap return checks and clean... |
| CVE-2026-46234 | HIGH | 7.8 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: vsock: fix buffer size clamping order In vsock_upd... |
| CVE-2026-46233 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: only purge non-released claims Wh... |
| CVE-2026-46232 | HIGH | 8.1 | 0.3% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_touch_reports A device... |
| CVE-2026-46231 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: put backbone reference on failed c... |
| CVE-2026-46230 | HIGH | 7.1 | 0.1% | May 28, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn3: Prevent OOB reads when parsing dec... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now