2026 CVE Vulnerabilities
64,617 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9560 | HIGH | 7.8 | 0.6% | May 26, 2026 | Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute ... |
| CVE-2026-9170 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper in... |
| CVE-2026-8856 | CRITICAL | 9.1 | 0.2% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to ... |
| CVE-2026-8855 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mut... |
| CVE-2026-8854 | HIGH | 7.5 | 0.4% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. |
| CVE-2026-8835 | HIGH | 7.3 | 0.3% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Admin... |
| CVE-2026-8834 | HIGH | 8 | 0.3% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administr... |
| CVE-2026-8633 | CRITICAL | 9.8 | 0.8% | May 26, 2026 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server... |
| CVE-2026-8620 | HIGH | 7.5 | 0.3% | May 26, 2026 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server... |
| CVE-2026-7454 | HIGH | 7.8 | 0.1% | May 26, 2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal... |
| CVE-2026-7453 | MEDIUM | 5.5 | 0.2% | May 26, 2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leadin... |
| CVE-2026-7452 | HIGH | 7.8 | 0.2% | May 26, 2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal... |
| CVE-2026-7451 | HIGH | 7.8 | 0.2% | May 26, 2026 | A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ... |
| CVE-2026-7450 | MEDIUM | 5.5 | 0.2% | May 26, 2026 | A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability... |
| CVE-2026-7251 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | Eppendorf BioFlo 320 is vulnerable due to VNC server using a hard-coded password. If a remote attacker knows the network... |
| CVE-2026-48696 | MEDIUM | 6.2 | 0.1% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 has a buffer overflow, a different vulnerability than CVE-2026-48686 and CVE-... |
| CVE-2026-48695 | HIGH | 8.1 | 1.1% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integra... |
| CVE-2026-48694 | HIGH | 8.1 | 0.2% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integr... |
| CVE-2026-47202 | CRITICAL | 9.3 | 0.2% | May 26, 2026 | Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unau... |
| CVE-2026-46624 | CRITICAL | 9.9 | 0.5% | May 26, 2026 | Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in ... |
| CVE-2026-44776 | MEDIUM | 5.9 | 0.3% | May 26, 2026 | Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do n... |
| CVE-2026-44775 | MEDIUM | 6.9 | 0.3% | May 26, 2026 | Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [All... |
| CVE-2026-44749 | MEDIUM | 4.3 | 0.3% | May 26, 2026 | The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request art... |
| CVE-2026-44730 | HIGH | 7.2 | 0.3% | May 26, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an ... |
| CVE-2026-44728 | HIGH | 7.8 | 0.1% | May 26, 2026 | Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now