2026 CVE Vulnerabilities
64,659 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41149 | MEDIUM | 5.3 | 0.4% | May 22, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 ... |
| CVE-2026-41148 | MEDIUM | 5.3 | 0.3% | May 22, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 ... |
| CVE-2026-41104 | HIGH | 7.5 | 0.9% | May 22, 2026 | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform... |
| CVE-2026-41090 | CRITICAL | 9.3 | 0.4% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-40412 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code ... |
| CVE-2026-40411 | HIGH | 8.8 | 0.5% | May 22, 2026 | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. |
| CVE-2026-35430 | HIGH | 8.8 | 0.4% | May 22, 2026 | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized atta... |
| CVE-2026-33843 | CRITICAL | 9.8 | 0.5% | May 22, 2026 | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized ... |
| CVE-2026-26147 | HIGH | 7.7 | 0.6% | May 22, 2026 | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. |
| CVE-2026-23663 | HIGH | 7.5 | 0.6% | May 22, 2026 | Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-23652 | CRITICAL | 9.8 | 0.6% | May 22, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an u... |
| CVE-2026-41147 | HIGH | 8.7 | 0.3% | May 22, 2026 | NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS)... |
| CVE-2026-41076 | HIGH | 8.1 | 0.4% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 t... |
| CVE-2026-41075 | HIGH | 8.8 | 0.3% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through ... |
| CVE-2026-41074 | HIGH | 7.1 | 0.1% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Si... |
| CVE-2026-41073 | MEDIUM | 4.6 | 0.2% | May 22, 2026 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.... |
| CVE-2026-41071 | HIGH | 8.1 | 0.3% | May 22, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file w... |
| CVE-2026-41069 | MEDIUM | 6.5 | 0.3% | May 22, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file... |
| CVE-2026-40864 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through ... |
| CVE-2026-3294 | HIGH | 8.8 | 0.4% | May 22, 2026 | An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjac... |
| CVE-2026-5843 | HIGH | 8.6 | 0.2% | May 22, 2026 | The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and exe... |
| CVE-2026-5817 | HIGH | 8.6 | 0.2% | May 22, 2026 | The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loadin... |
| CVE-2026-40610 | MEDIUM | 5.5 | 0.3% | May 22, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1... |
| CVE-2026-40607 | HIGH | 7.5 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerabi... |
| CVE-2026-40598 | MEDIUM | 6.9 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now