2026 CVE Vulnerabilities
64,659 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39832 | CRITICAL | 9.1 | 0.6% | May 22, 2026 | When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serializ... |
| CVE-2026-39831 | CRITICAL | 9.1 | 0.4% | May 22, 2026 | The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did... |
| CVE-2026-39830 | CRITICAL | 9.1 | 0.6% | May 22, 2026 | A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection... |
| CVE-2026-39829 | HIGH | 7.5 | 0.5% | May 22, 2026 | The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessive... |
| CVE-2026-39828 | MEDIUM | 6.3 | 0.4% | May 22, 2026 | When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were... |
| CVE-2026-39827 | MEDIUM | 6.5 | 0.2% | May 22, 2026 | An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory gr... |
| CVE-2026-9264 | CRITICAL | 9.3 | 0.2% | May 22, 2026 | A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution an... |
| CVE-2026-34911 | HIGH | 7.7 | 0.7% | May 22, 2026 | A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in Un... |
| CVE-2026-34910 | CRITICAL | 10 | 78.6% | May 22, 2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS ... |
| CVE-2026-34909 | CRITICAL | 10 | 2.3% | May 22, 2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to a... |
| CVE-2026-34908 | CRITICAL | 10 | 2.5% | May 22, 2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS de... |
| CVE-2026-33000 | CRITICAL | 9.1 | 1.1% | May 22, 2026 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerabilit... |
| CVE-2026-5297 | — | — | — | May 21, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-8435 | MEDIUM | 6.5 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file appr... |
| CVE-2026-8434 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc... |
| CVE-2026-8433 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file resc... |
| CVE-2026-8432 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star... |
| CVE-2026-8427 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file remo... |
| CVE-2026-8416 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addF... |
| CVE-2026-8415 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/as... |
| CVE-2026-8414 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/dupl... |
| CVE-2026-8413 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/... |
| CVE-2026-8412 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk... |
| CVE-2026-8411 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/... |
| CVE-2026-8410 | HIGH | 8.8 | 0.1% | May 21, 2026 | Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now