2026 CVE Vulnerabilities
64,659 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8353 | MEDIUM | 4.8 | 0.1% | May 22, 2026 | Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inje... |
| CVE-2026-8347 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog... |
| CVE-2026-8340 | MEDIUM | 4.3 | 0.1% | May 22, 2026 | Concrete CMS 9.5.0 and below is vulnerable to CSRF via Backend\File::approveVersion. Victim with edit_file_contents perm... |
| CVE-2026-9277 | HIGH | 8.1 | 0.8% | May 22, 2026 | shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The ... |
| CVE-2026-8997 | MEDIUM | 4.8 | 0.1% | May 22, 2026 | vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json)... |
| CVE-2026-8673 | CRITICAL | 9.1 | 0.2% | May 22, 2026 | Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Atta... |
| CVE-2026-8672 | MEDIUM | 5.1 | 0.1% | May 22, 2026 | Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default User... |
| CVE-2026-8671 | HIGH | 7.5 | 0.2% | May 22, 2026 | Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows R... |
| CVE-2026-8670 | CRITICAL | 9.6 | 0.2% | May 22, 2026 | Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session ID... |
| CVE-2026-44930 | CRITICAL | 9.8 | 0.7% | May 22, 2026 | An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacke... |
| CVE-2026-44618 | MEDIUM | 5.3 | 0.3% | May 22, 2026 | Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users a... |
| CVE-2026-44417 | HIGH | 7.5 | 0.6% | May 22, 2026 | The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that anoth... |
| CVE-2026-5755 | MEDIUM | 6.5 | 0.2% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to ... |
| CVE-2026-5740 | HIGH | 7.5 | 0.3% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate ... |
| CVE-2026-5308 | HIGH | 7.5 | 0.3% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo... |
| CVE-2026-4646 | MEDIUM | 4.3 | 0.3% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp... |
| CVE-2026-4635 | MEDIUM | 5.3 | 0.2% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channe... |
| CVE-2026-3636 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team memb... |
| CVE-2026-3473 | HIGH | 7.1 | 0.1% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne... |
| CVE-2026-25608 | LOW | 2.3 | 0.2% | May 22, 2026 | STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middl... |
| CVE-2026-25607 | MEDIUM | 5.7 | 0.1% | May 22, 2026 | Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzin... |
| CVE-2026-25606 | HIGH | 8.7 | 0.2% | May 22, 2026 | A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multip... |
| CVE-2026-9011 | HIGH | 7.5 | 0.4% | May 22, 2026 | The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in al... |
| CVE-2026-8692 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to... |
| CVE-2026-8684 | MEDIUM | 5.3 | 0.3% | May 22, 2026 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now