2026 CVE Vulnerabilities
64,659 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9342 | MEDIUM | 6.3 | 0.2% | May 23, 2026 | A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an un... |
| CVE-2026-9306 | LOW | 3.7 | 0.3% | May 23, 2026 | A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourne... |
| CVE-2026-9305 | MEDIUM | 6.3 | 0.2% | May 23, 2026 | A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUp... |
| CVE-2026-9304 | MEDIUM | 5 | 0.2% | May 23, 2026 | A security flaw has been discovered in calcom cal.diy up to 4.9.4. The affected element is the function validateUrlForSS... |
| CVE-2026-9303 | MEDIUM | 4.3 | 0.2% | May 23, 2026 | A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to... |
| CVE-2026-9302 | MEDIUM | 6.3 | 0.2% | May 23, 2026 | A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. Thi... |
| CVE-2026-9301 | MEDIUM | 6.3 | 0.2% | May 23, 2026 | A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGRe... |
| CVE-2026-9300 | MEDIUM | 6.3 | 0.2% | May 23, 2026 | A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupReq... |
| CVE-2026-46300 | HIGH | 7.8 | 9.5% | May 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coa... |
| CVE-2026-43503 | HIGH | 8.8 | 0.3% | May 23, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: propagate shared-frag marker through f... |
| CVE-2026-9299 | MEDIUM | 6.3 | 0.2% | May 23, 2026 | A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIn... |
| CVE-2026-9298 | MEDIUM | 6.3 | 0.2% | May 23, 2026 | A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an unknown functionality... |
| CVE-2026-9297 | MEDIUM | 6.3 | 1.4% | May 23, 2026 | A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /g... |
| CVE-2026-9296 | MEDIUM | 6.3 | 1.2% | May 23, 2026 | A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM ... |
| CVE-2026-9295 | HIGH | 8.8 | 0.5% | May 23, 2026 | A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /gof... |
| CVE-2026-9294 | HIGH | 8.8 | 0.5% | May 23, 2026 | A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the f... |
| CVE-2026-9284 | HIGH | 8.2 | 0.4% | May 23, 2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information di... |
| CVE-2026-6898 | HIGH | 8.8 | 0.2% | May 23, 2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2026-6897 | HIGH | 8.8 | 0.2% | May 23, 2026 | The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2026-6895 | HIGH | 8.8 | 0.2% | May 23, 2026 | The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclos... |
| CVE-2026-6419 | HIGH | 8.8 | 0.3% | May 23, 2026 | The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up ... |
| CVE-2026-47280 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a net... |
| CVE-2026-45659 | HIGH | 8.8 | 3.2% | May 22, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a ne... |
| CVE-2026-42901 | CRITICAL | 10 | 0.3% | May 22, 2026 | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-42827 | HIGH | 7.5 | 0.5% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now