2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23734 | CRITICAL | 9.3 | 19.5% | May 20, 2026 | XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to ... |
| CVE-2026-30691 | MEDIUM | 6.1 | 0.3% | May 20, 2026 | Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitra... |
| CVE-2026-20240 | MEDIUM | 6.5 | 0.4% | May 20, 2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-20239 | MEDIUM | 6.5 | 0.5% | May 20, 2026 | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.1... |
| CVE-2026-20238 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could a... |
| CVE-2026-9101 | MEDIUM | 4.3 | 0.5% | May 20, 2026 | Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering she... |
| CVE-2026-9100 | HIGH | 7.1 | 0.4% | May 20, 2026 | The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. ... |
| CVE-2026-9087 | HIGH | 8.1 | 0.3% | May 20, 2026 | A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not ... |
| CVE-2026-8342 | — | — | — | May 20, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-7613 | HIGH | 7.2 | 0.3% | May 20, 2026 | The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0]... |
| CVE-2026-44926 | HIGH | 8.8 | 0.4% | May 20, 2026 | InfoScale CmdServer before 7.4.2 mishandles access control. |
| CVE-2026-44925 | HIGH | 8.8 | 0.2% | May 20, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to for... |
| CVE-2026-44924 | MEDIUM | 5.4 | 0.2% | May 20, 2026 | InfoScale VIOM 9.1.3 allows XSS. |
| CVE-2026-44923 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. |
| CVE-2026-20223 | CRITICAL | 10 | 0.8% | May 20, 2026 | A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthentica... |
| CVE-2026-20206 | MEDIUM | 6.3 | 0.4% | May 20, 2026 | A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, ... |
| CVE-2026-20199 | HIGH | 7.2 | 0.4% | May 20, 2026 | A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, re... |
| CVE-2026-20171 | MEDIUM | 6.8 | 0.5% | May 20, 2026 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switc... |
| CVE-2026-9084 | MEDIUM | 6 | 0.2% | May 20, 2026 | MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based ... |
| CVE-2026-8598 | CRITICAL | 9.1 | 0.5% | May 20, 2026 | An undocumented configuration export port is accessible on some models of ZKTeco CCTV cameras. This port does not requi... |
| CVE-2026-8488 | HIGH | 7.5 | 0.4% | May 20, 2026 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessi... |
| CVE-2026-8487 | HIGH | 7.5 | 0.3% | May 20, 2026 | Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Da... |
| CVE-2026-8486 | HIGH | 7.5 | 0.4% | May 20, 2026 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Floodin... |
| CVE-2026-5783 | HIGH | 7.6 | 0.2% | May 20, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Sof... |
| CVE-2026-4293 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now