2026 CVE Vulnerabilities
64,617 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48687 | CRITICAL | 9.8 | 1.6% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integrat... |
| CVE-2026-48686 | CRITICAL | 9.8 | 0.6% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachab... |
| CVE-2026-48685 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attrib... |
| CVE-2026-48684 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In ... |
| CVE-2026-48683 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset p... |
| CVE-2026-46620 | MEDIUM | 6.5 | 0.1% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on c... |
| CVE-2026-43936 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of... |
| CVE-2026-43935 | HIGH | 8.1 | 0.3% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p... |
| CVE-2026-43934 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the applicati... |
| CVE-2026-40564 | MEDIUM | 6.5 | 0.5% | May 26, 2026 | Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Ku... |
| CVE-2026-38587 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw ex... |
| CVE-2026-25112 | HIGH | 7.8 | 0.1% | May 26, 2026 | A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack. |
| CVE-2026-9552 | HIGH | 7.3 | 0.3% | May 26, 2026 | A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown c... |
| CVE-2026-9551 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of ... |
| CVE-2026-9550 | HIGH | 7.3 | 0.5% | May 26, 2026 | A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0.... |
| CVE-2026-4480 | CRITICAL | 9 | 13.9% | May 26, 2026 | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the comma... |
| CVE-2026-46368 | HIGH | 8.8 | 6.6% | May 26, 2026 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distribu... |
| CVE-2026-45247 | CRITICAL | 9.8 | 27.5% | May 26, 2026 | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that ... |
| CVE-2026-45082 | HIGH | 7.6 | 0.3% | May 26, 2026 | Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability... |
| CVE-2026-43919 | — | — | — | May 26, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason: This candidate is a ... |
| CVE-2026-42785 | HIGH | 8.6 | 0.7% | May 26, 2026 | OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitra... |
| CVE-2026-42425 | HIGH | 8.6 | 0.6% | May 26, 2026 | OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to exe... |
| CVE-2026-42347 | — | — | — | May 26, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-28496. Reason: This candidate is a ... |
| CVE-2026-41917 | MEDIUM | 6.9 | 0.4% | May 26, 2026 | OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scriptin... |
| CVE-2026-41401 | HIGH | 7.1 | 0.5% | May 26, 2026 | libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly up... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now