2026 CVE Vulnerabilities
64,471 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21785 | MEDIUM | 4 | 0.1% | May 27, 2026 | A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlie... |
| CVE-2026-9759 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service |
| CVE-2026-8364 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes r... |
| CVE-2026-8363 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with ... |
| CVE-2026-8362 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with... |
| CVE-2026-8361 | HIGH | 7.5 | 0.4% | May 27, 2026 | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome |
| CVE-2026-8360 | HIGH | 7.5 | 0.3% | May 27, 2026 | Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWe... |
| CVE-2026-8359 | HIGH | 7.5 | 0.3% | May 27, 2026 | When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to ... |
| CVE-2026-49009 | LOW | 3.1 | 0.5% | May 27, 2026 | Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. |
| CVE-2026-48792 | MEDIUM | 4.4 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/evdev.c silently ... |
| CVE-2026-48066 | MEDIUM | 5.7 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/log.c contains a ... |
| CVE-2026-48065 | MEDIUM | 6.7 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, src/conf.c allocates ... |
| CVE-2026-48064 | HIGH | 8.1 | 0.3% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is... |
| CVE-2026-47274 | MEDIUM | 6.3 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, multiple pam_usb help... |
| CVE-2026-47273 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath ... |
| CVE-2026-47272 | HIGH | 7.1 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare(... |
| CVE-2026-47271 | MEDIUM | 5.1 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented... |
| CVE-2026-47161 | HIGH | 8.7 | 0.5% | May 27, 2026 | RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configure... |
| CVE-2026-45134 | HIGH | 7.1 | 0.2% | May 27, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and... |
| CVE-2026-45108 | HIGH | 8.4 | 0.2% | May 27, 2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, ... |
| CVE-2026-45104 | HIGH | 7.5 | 0.3% | May 27, 2026 | MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always ... |
| CVE-2026-45102 | CRITICAL | 9.9 | 0.3% | May 27, 2026 | OneUptime is an open-source monitoring and observability platform. Prior to 10.0.98, OneUptime uses the Node.js' vm modu... |
| CVE-2026-44888 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's SaveConfigFile()... |
| CVE-2026-44887 | CRITICAL | 9.8 | 0.5% | May 27, 2026 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based config... |
| CVE-2026-44886 | HIGH | 8.7 | 0.2% | May 27, 2026 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web ap... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now