2026 CVE Vulnerabilities
64,617 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9580 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepa... |
| CVE-2026-9579 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/logi... |
| CVE-2026-8676 | HIGH | 8.8 | 0.2% | May 26, 2026 | An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bo... |
| CVE-2026-48593 | MEDIUM | 5.9 | 0.3% | May 26, 2026 | Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory e... |
| CVE-2026-48592 | MEDIUM | 5.3 | 0.4% | May 26, 2026 | Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthor... |
| CVE-2026-47672 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any networ... |
| CVE-2026-45575 | HIGH | 7.4 | 0.1% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who ... |
| CVE-2026-45413 | MEDIUM | 6.9 | 0.1% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes... |
| CVE-2026-45412 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated u... |
| CVE-2026-44899 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the... |
| CVE-2026-44898 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-c... |
| CVE-2026-44897 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the openin... |
| CVE-2026-44896 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py... |
| CVE-2026-44847 | HIGH | 7.5 | 0.3% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/w... |
| CVE-2026-44844 | MEDIUM | 6.3 | 0.4% | May 26, 2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well... |
| CVE-2026-44843 | HIGH | 8.2 | 0.4% | May 26, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains... |
| CVE-2026-44837 | HIGH | 7.5 | 0.4% | May 26, 2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3... |
| CVE-2026-44836 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3... |
| CVE-2026-44708 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline m... |
| CVE-2026-44451 | CRITICAL | 9.3 | 0.2% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied... |
| CVE-2026-44450 | CRITICAL | 9.9 | 0.4% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command... |
| CVE-2026-44449 | CRITICAL | 9.1 | 0.5% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the ... |
| CVE-2026-44444 | CRITICAL | 9.1 | 0.4% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install... |
| CVE-2026-44443 | MEDIUM | 4.8 | 0.1% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level varia... |
| CVE-2026-44209 | HIGH | 7.5 | 0.5% | May 26, 2026 | Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Env... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now