2026 CVE Vulnerabilities
64,617 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8647 | MEDIUM | 4.8 | 0.2% | May 26, 2026 | Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. ... |
| CVE-2026-46740 | MEDIUM | 5.3 | 0.3% | May 26, 2026 | Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values w... |
| CVE-2026-9603 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown... |
| CVE-2026-9584 | HIGH | 7.3 | 0.3% | May 26, 2026 | A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown functi... |
| CVE-2026-5260 | HIGH | 8.2 | 0.7% | May 26, 2026 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key excha... |
| CVE-2026-48710 | MEDIUM | 6.5 | 36.3% | May 26, 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not valida... |
| CVE-2026-45574 | HIGH | 8.1 | 0.1% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on t... |
| CVE-2026-45298 | HIGH | 8.6 | 1.5% | May 26, 2026 | Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quick... |
| CVE-2026-44985 | CRITICAL | 9.6 | 0.2% | May 26, 2026 | Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach ... |
| CVE-2026-44983 | HIGH | 7.3 | 0.2% | May 26, 2026 | smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the inter... |
| CVE-2026-44966 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pol... |
| CVE-2026-44905 | HIGH | 7.5 | 0.2% | May 26, 2026 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vul... |
| CVE-2026-44903 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the ... |
| CVE-2026-44900 | HIGH | 8.1 | 0.1% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublic... |
| CVE-2026-44895 | CRITICAL | 9.2 | 0.4% | May 26, 2026 | GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships... |
| CVE-2026-44788 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a pa... |
| CVE-2026-44213 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Inst... |
| CVE-2026-43988 | HIGH | 7.5 | 0.2% | May 26, 2026 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vul... |
| CVE-2026-42015 | MEDIUM | 5.3 | 0.7% | May 26, 2026 | A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allow... |
| CVE-2026-42013 | HIGH | 8.2 | 0.4% | May 26, 2026 | A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the va... |
| CVE-2026-42012 | HIGH | 7.1 | 0.4% | May 26, 2026 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certifi... |
| CVE-2026-9642 | — | — | — | May 26, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-9583 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This imp... |
| CVE-2026-9582 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Thi... |
| CVE-2026-9581 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now