2026 CVE Vulnerabilities
64,474 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49047 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-49046 | HIGH | 8.5 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Dupli... |
| CVE-2026-49045 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-49044 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advan... |
| CVE-2026-48973 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2026-48927 | MEDIUM | 5.5 | 0.2% | May 27, 2026 | Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting... |
| CVE-2026-48926 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allow... |
| CVE-2026-48925 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attacker... |
| CVE-2026-48924 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to pe... |
| CVE-2026-48923 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation... |
| CVE-2026-48922 | HIGH | 7.5 | 0.4% | May 27, 2026 | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip... |
| CVE-2026-48921 | HIGH | 7.5 | 0.3% | May 27, 2026 | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared l... |
| CVE-2026-48920 | HIGH | 8.8 | 0.3% | May 27, 2026 | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by set... |
| CVE-2026-48919 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. |
| CVE-2026-48918 | MEDIUM | 6.6 | 0.2% | May 27, 2026 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. |
| CVE-2026-48917 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation. |
| CVE-2026-48916 | MEDIUM | 6.6 | 0.3% | May 27, 2026 | Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals. |
| CVE-2026-48545 | MEDIUM | 6.8 | 0.4% | May 27, 2026 | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa... |
| CVE-2026-48544 | HIGH | 8.7 | 0.4% | May 27, 2026 | Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() metho... |
| CVE-2026-47119 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arb... |
| CVE-2026-47118 | HIGH | 7.1 | 0.4% | May 27, 2026 | Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arb... |
| CVE-2026-45571 | MEDIUM | 5.4 | 0.3% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validat... |
| CVE-2026-45570 | CRITICAL | 9.6 | 0.4% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH t... |
| CVE-2026-45022 | HIGH | 7.5 | 0.2% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may par... |
| CVE-2026-44988 | HIGH | 8.8 | 0.2% | May 27, 2026 | LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now