2026 CVE Vulnerabilities
64,602 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44325 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /o... |
| CVE-2026-44324 | MEDIUM | 6.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscript... |
| CVE-2026-44323 | MEDIUM | 6.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscript... |
| CVE-2026-44322 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-managemen... |
| CVE-2026-44321 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management... |
| CVE-2026-44320 | HIGH | 7.3 | 0.2% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback ... |
| CVE-2026-44319 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire pro... |
| CVE-2026-44318 | MEDIUM | 5.3 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/s... |
| CVE-2026-44317 | MEDIUM | 6.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthoriz... |
| CVE-2026-44316 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-smpolicycontro... |
| CVE-2026-44315 | CRITICAL | 9.4 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-manag... |
| CVE-2026-42790 | HIGH | 8.1 | 0.3% | May 27, 2026 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS... |
| CVE-2026-42459 | HIGH | 7.5 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to vali... |
| CVE-2026-42083 | HIGH | 8.2 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authen... |
| CVE-2026-42082 | MEDIUM | 5.4 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the... |
| CVE-2026-42081 | HIGH | 7.1 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the ... |
| CVE-2026-38945 | HIGH | 7.8 | 0.8% | May 27, 2026 | Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary cod... |
| CVE-2026-38931 | MEDIUM | 5.4 | 0.2% | May 27, 2026 | A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp ... |
| CVE-2026-38930 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component... |
| CVE-2026-9712 | LOW | 3.8 | 0.2% | May 27, 2026 | When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, ra... |
| CVE-2026-9674 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows atta... |
| CVE-2026-6957 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr... |
| CVE-2026-49103 | CRITICAL | 9.4 | 0.3% | May 27, 2026 | Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. Thi... |
| CVE-2026-49102 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes compo... |
| CVE-2026-49059 | MEDIUM | 4.7 | 0.2% | May 27, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now