2026 CVE Vulnerabilities
64,617 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40034 | HIGH | 8.5 | 0.4% | May 26, 2026 | gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmo... |
| CVE-2026-40033 | HIGH | 8.8 | 0.9% | May 26, 2026 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers t... |
| CVE-2026-9544 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by thi... |
| CVE-2026-9543 | CRITICAL | 9.8 | 2.1% | May 26, 2026 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the fi... |
| CVE-2026-9542 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of ... |
| CVE-2026-9541 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqob... |
| CVE-2026-9540 | MEDIUM | 5.5 | 0.4% | May 26, 2026 | A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component ... |
| CVE-2026-8479 | MEDIUM | 6.9 | 0.2% | May 26, 2026 | IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially craf... |
| CVE-2026-8174 | MEDIUM | 5.7 | 0.4% | May 26, 2026 | Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wo... |
| CVE-2026-7374 | CRITICAL | 9.9 | 0.7% | May 26, 2026 | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with ed... |
| CVE-2026-7310 | MEDIUM | 4.4 | 0.1% | May 26, 2026 | A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious ... |
| CVE-2026-48136 | MEDIUM | 4.1 | 4.1% | May 26, 2026 | When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access... |
| CVE-2026-48135 | MEDIUM | 5.3 | 2.6% | May 26, 2026 | A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa... |
| CVE-2026-48134 | MEDIUM | 5.6 | 4.4% | May 26, 2026 | When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific... |
| CVE-2026-48133 | HIGH | 7.5 | 4.8% | May 26, 2026 | When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to r... |
| CVE-2026-48132 | HIGH | 8.1 | 2.1% | May 26, 2026 | The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As... |
| CVE-2026-48131 | HIGH | 8.1 | 2.7% | May 26, 2026 | The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage o... |
| CVE-2026-44410 | LOW | 3.8 | 0.1% | May 26, 2026 | This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended... |
| CVE-2026-39661 | HIGH | 7.5 | 0.4% | May 26, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39642 | MEDIUM | 5.3 | 0.3% | May 26, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code... |
| CVE-2026-27427 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mas... |
| CVE-2026-25713 | HIGH | 7.8 | 0.2% | May 26, 2026 | A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01)... |
| CVE-2026-25104 | HIGH | 7.8 | 0.2% | May 26, 2026 | A heap-based buffer overflow vulnerability exists in the LXF parsing functionality of MediaInfoLib (version(s): 26.01). ... |
| CVE-2026-24638 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-24590 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Config... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now