2026 CVE Vulnerabilities
64,617 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8850 | HIGH | 7.5 | 0.4% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload. |
| CVE-2026-48905 | MEDIUM | 6.1 | 0.1% | May 26, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. |
| CVE-2026-48904 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | An improper access check allows privelege escalation through the com_users group editing webservice endpoint. |
| CVE-2026-48903 | MEDIUM | 6.1 | 0.1% | May 26, 2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. |
| CVE-2026-48902 | CRITICAL | 9.8 | 0.2% | May 26, 2026 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't e... |
| CVE-2026-48901 | HIGH | 7.5 | 0.2% | May 26, 2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. |
| CVE-2026-48900 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. |
| CVE-2026-48899 | CRITICAL | 9.8 | 0.2% | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. |
| CVE-2026-48898 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | An improper access check allows privilege escalation through the com_users batch task. |
| CVE-2026-48897 | HIGH | 7.5 | 0.2% | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48896 | HIGH | 7.5 | 0.3% | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48864 | HIGH | 7.8 | 0.2% | May 26, 2026 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed... |
| CVE-2026-48697 | HIGH | 7.4 | 0.2% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_w... |
| CVE-2026-48693 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. T... |
| CVE-2026-48691 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp... |
| CVE-2026-48690 | HIGH | 7.1 | 0.1% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer alloc... |
| CVE-2026-48126 | HIGH | 8.2 | 0.3% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let... |
| CVE-2026-48091 | — | — | — | May 26, 2026 | Rejected reason: Further research determined the issue is not a vulnerability. |
| CVE-2026-47728 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID wi... |
| CVE-2026-47716 | LOW | 3.1 | 0.1% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes acces... |
| CVE-2026-47715 | LOW | 3.1 | 0.2% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier... |
| CVE-2026-46431 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Orig... |
| CVE-2026-46430 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Li... |
| CVE-2026-45836 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_... |
| CVE-2026-45835 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now