2026 CVE Vulnerabilities
64,369 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47675 | MEDIUM | 5.3 | 0.2% | May 28, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() ... |
| CVE-2026-47674 | MEDIUM | 5.3 | 0.2% | May 28, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restricti... |
| CVE-2026-47673 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk ... |
| CVE-2026-45292 | MEDIUM | 5.3 | 1.1% | May 28, 2026 | opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing tel... |
| CVE-2026-45261 | CRITICAL | 9.3 | 0.5% | May 28, 2026 | GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execut... |
| CVE-2026-45078 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synaps... |
| CVE-2026-45076 | LOW | 2.7 | 0.4% | May 28, 2026 | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers ... |
| CVE-2026-44543 | HIGH | 8.7 | 0.4% | May 28, 2026 | Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.3... |
| CVE-2026-44477 | CRITICAL | 9.9 | 0.5% | May 28, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and ... |
| CVE-2026-44466 | HIGH | 8.6 | 0.2% | May 28, 2026 | Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expans... |
| CVE-2026-44465 | HIGH | 8.6 | 0.3% | May 28, 2026 | Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/... |
| CVE-2026-44463 | HIGH | 7.8 | 0.2% | May 28, 2026 | Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment ... |
| CVE-2026-44462 | HIGH | 8.8 | 0.4% | May 28, 2026 | Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansio... |
| CVE-2026-44461 | HIGH | 8.6 | 0.3% | May 28, 2026 | Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with ex... |
| CVE-2026-41185 | MEDIUM | 6.5 | 0.3% | May 28, 2026 | When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to at... |
| CVE-2026-41184 | MEDIUM | 6.5 | 0.5% | May 28, 2026 | In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration... |
| CVE-2026-41160 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Ac... |
| CVE-2026-41141 | MEDIUM | 6.5 | 0.3% | May 28, 2026 | EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:... |
| CVE-2026-38707 | CRITICAL | 9.8 | 1.2% | May 28, 2026 | A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firm... |
| CVE-2026-38704 | CRITICAL | 9.8 | 1.3% | May 28, 2026 | A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 ... |
| CVE-2026-38703 | CRITICAL | 9.8 | 1.2% | May 28, 2026 | A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 f... |
| CVE-2026-38702 | CRITICAL | 9.8 | 1.2% | May 28, 2026 | A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 f... |
| CVE-2026-24444 | CRITICAL | 9.8 | 0.5% | May 28, 2026 | SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability ... |
| CVE-2026-48735 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr... |
| CVE-2026-48526 | HIGH | 7.4 | 0.4% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now