2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39047 | HIGH | 7.5 | 0.6% | May 20, 2026 | Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Prin... |
| CVE-2026-8485 | HIGH | 7.5 | 0.3% | May 20, 2026 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i... |
| CVE-2026-8469 | HIGH | 8.2 | 0.5% | May 20, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthentic... |
| CVE-2026-8467 | CRITICAL | 9.5 | 0.9% | May 20, 2026 | Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanit... |
| CVE-2026-47068 | LOW | 2.3 | 0.4% | May 20, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session P... |
| CVE-2026-24425 | CRITICAL | 9.9 | 0.7% | May 20, 2026 | Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface ... |
| CVE-2026-22554 | HIGH | 7.8 | 0.2% | May 20, 2026 | A heap-based buffer overflow vulnerability exists in the Channel Splitting functionality of MediaInfoLib (version(s): 26... |
| CVE-2026-21836 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, documen... |
| CVE-2026-5950 | MEDIUM | 5.3 | 0.6% | May 20, 2026 | An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling ... |
| CVE-2026-5947 | MEDIUM | 5.9 | 1.4% | May 20, 2026 | Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incomi... |
| CVE-2026-5946 | HIGH | 7.5 | 1.9% | May 20, 2026 | Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`... |
| CVE-2026-45584 | HIGH | 8.1 | 0.9% | May 20, 2026 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. |
| CVE-2026-45498 | HIGH | 7.5 | 63.1% | May 20, 2026 | Microsoft Defender Denial of Service Vulnerability |
| CVE-2026-45443 | MEDIUM | 5 | 0.2% | May 20, 2026 | Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Explo... |
| CVE-2026-42834 | HIGH | 7.8 | 0.4% | May 20, 2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-42383 | HIGH | 7.6 | 0.3% | May 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooComme... |
| CVE-2026-41091 | HIGH | 7.8 | 8.4% | May 20, 2026 | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to el... |
| CVE-2026-3593 | CRITICAL | 9.8 | 1.5% | May 20, 2026 | A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.... |
| CVE-2026-3592 | MEDIUM | 5.3 | 0.4% | May 20, 2026 | BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a quer... |
| CVE-2026-3039 | HIGH | 7.5 | 1.0% | May 20, 2026 | BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory ... |
| CVE-2026-29518 | HIGH | 7 | 0.2% | May 20, 2026 | Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that ... |
| CVE-2026-27424 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Confi... |
| CVE-2026-27405 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-24573 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualiz... |
| CVE-2026-25602 | LOW | 2.3 | 0.1% | May 20, 2026 | Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server)... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now