2026 CVE Vulnerabilities
64,658 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9450 | MEDIUM | 6.3 | 0.2% | May 25, 2026 | A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of ... |
| CVE-2026-9449 | MEDIUM | 6.3 | 0.2% | May 25, 2026 | A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the ... |
| CVE-2026-9448 | MEDIUM | 4.3 | 0.3% | May 25, 2026 | A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the ... |
| CVE-2026-9447 | HIGH | 7.3 | 0.3% | May 25, 2026 | A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown func... |
| CVE-2026-46745 | MEDIUM | 5.3 | 0.6% | May 25, 2026 | Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated att... |
| CVE-2026-40127 | MEDIUM | 5.3 | 0.3% | May 25, 2026 | OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID par... |
| CVE-2026-9446 | MEDIUM | 4.7 | 0.3% | May 25, 2026 | A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown... |
| CVE-2026-9445 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file... |
| CVE-2026-9444 | MEDIUM | 4.7 | 0.3% | May 25, 2026 | A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function dele... |
| CVE-2026-9443 | HIGH | 8.8 | 0.6% | May 25, 2026 | A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSet... |
| CVE-2026-9442 | HIGH | 8.8 | 0.6% | May 25, 2026 | A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /gofor... |
| CVE-2026-9441 | MEDIUM | 6.3 | 1.4% | May 25, 2026 | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of th... |
| CVE-2026-9274 | MEDIUM | 5.2 | 0.1% | May 25, 2026 | This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory.... |
| CVE-2026-5223 | MEDIUM | 5.3 | 0.3% | May 25, 2026 | Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious... |
| CVE-2026-5222 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. I... |
| CVE-2026-45361 | HIGH | 8.1 | 0.6% | May 25, 2026 | Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH tra... |
| CVE-2026-9490 | MEDIUM | 5.5 | 0.2% | May 25, 2026 | A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a we... |
| CVE-2026-9440 | MEDIUM | 6.3 | 1.4% | May 25, 2026 | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of th... |
| CVE-2026-9439 | MEDIUM | 6.3 | 1.2% | May 25, 2026 | A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. T... |
| CVE-2026-9438 | MEDIUM | 5.4 | 0.3% | May 25, 2026 | A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This imp... |
| CVE-2026-9437 | MEDIUM | 6.3 | 1.4% | May 25, 2026 | A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API.... |
| CVE-2026-9436 | CRITICAL | 9.8 | 2.0% | May 25, 2026 | A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of ... |
| CVE-2026-9435 | CRITICAL | 9.8 | 1.9% | May 25, 2026 | A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of ... |
| CVE-2026-4915 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil element... |
| CVE-2026-45249 | MEDIUM | 6.1 | 0.8% | May 25, 2026 | A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. Thi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now