2026 CVE Vulnerabilities
64,659 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40597 | HIGH | 7.6 | 0.5% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS ... |
| CVE-2026-40596 | HIGH | 7.2 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated us... |
| CVE-2026-40295 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module... |
| CVE-2026-39824 | LOW | 3.3 | 0.1% | May 22, 2026 | NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum siz... |
| CVE-2026-9291 | HIGH | 7.5 | 0.4% | May 22, 2026 | Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remot... |
| CVE-2026-6406 | HIGH | 8.8 | 0.2% | May 22, 2026 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When EC... |
| CVE-2026-48700 | CRITICAL | 9.3 | 0.2% | May 22, 2026 | An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI... |
| CVE-2026-40172 | HIGH | 8.1 | 0.5% | May 22, 2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PAT... |
| CVE-2026-40166 | HIGH | 7.1 | 0.5% | May 22, 2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent... |
| CVE-2026-39970 | HIGH | 8.5 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.type... |
| CVE-2026-39969 | MEDIUM | 6.5 | 0.1% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/works... |
| CVE-2026-39968 | HIGH | 7.1 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via ... |
| CVE-2026-39967 | LOW | 3.1 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter r... |
| CVE-2026-39966 | MEDIUM | 6.5 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions t... |
| CVE-2026-46727 | HIGH | 8.1 | 0.5% | May 22, 2026 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getadd... |
| CVE-2026-42627 | MEDIUM | 6.2 | 0.1% | May 22, 2026 | In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a craft... |
| CVE-2026-39965 | HIGH | 7.7 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Reques... |
| CVE-2026-39964 | MEDIUM | 5.4 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor t... |
| CVE-2026-9255 | HIGH | 8.4 | 0.1% | May 22, 2026 | Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to ex... |
| CVE-2026-42626 | MEDIUM | 5.9 | 0.2% | May 22, 2026 | HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD... |
| CVE-2026-37470 | HIGH | 7.3 | 0.3% | May 22, 2026 | An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login p... |
| CVE-2026-36228 | HIGH | 7.3 | 0.4% | May 22, 2026 | Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu... |
| CVE-2026-36227 | MEDIUM | 6.5 | 0.9% | May 22, 2026 | Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and e... |
| CVE-2026-36226 | MEDIUM | 6.1 | 0.3% | May 22, 2026 | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensit... |
| CVE-2026-34207 | HIGH | 7.6 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks valida... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now