2026 CVE Vulnerabilities
64,617 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45834 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_... |
| CVE-2026-45728 | HIGH | 7.5 | 0.3% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path... |
| CVE-2026-45721 | CRITICAL | 9 | 0.4% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is asked for any URL path that res... |
| CVE-2026-44729 | HIGH | 8.7 | 0.3% | May 26, 2026 | Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fil... |
| CVE-2026-44723 | CRITICAL | 9.9 | 0.5% | May 26, 2026 | Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pul... |
| CVE-2026-44680 | HIGH | 7.6 | 1.3% | May 26, 2026 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-o... |
| CVE-2026-44502 | MEDIUM | 4.3 | 0.3% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypa... |
| CVE-2026-44314 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device ... |
| CVE-2026-43982 | HIGH | 8.7 | 0.3% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go use... |
| CVE-2026-43981 | HIGH | 8.2 | 0.2% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protec... |
| CVE-2026-40384 | HIGH | 7.5 | 0.4% | May 26, 2026 | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerabili... |
| CVE-2026-40383 | CRITICAL | 9.8 | 0.5% | May 26, 2026 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. |
| CVE-2026-35223 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | An improper access check allows unauthorized access to com_config webservice endpoints. |
| CVE-2026-35222 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. |
| CVE-2026-35221 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. |
| CVE-2026-35220 | MEDIUM | 4.3 | 0.1% | May 26, 2026 | Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. |
| CVE-2026-30895 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. |
| CVE-2026-30894 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the content history component. |
| CVE-2026-2264 | CRITICAL | 9.2 | 0.4% | May 26, 2026 | A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side ... |
| CVE-2026-25901 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. |
| CVE-2026-25900 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the feed modules. |
| CVE-2026-24212 | CRITICAL | 9.8 | 0.7% | May 26, 2026 | NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A s... |
| CVE-2026-24162 | HIGH | 7.8 | 0.4% | May 26, 2026 | NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of unt... |
| CVE-2026-48692 | HIGH | 8.1 | 0.2% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The... |
| CVE-2026-48688 | HIGH | 7.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now