2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34579 | MEDIUM | 5.3 | 0.4% | May 19, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization... |
| CVE-2026-5090 | MEDIUM | 6.1 | 0.3% | May 19, 2026 | Template::Plugin::HTML versions before 3.103 for Perl allows HTML and JavaScript to be injected. The html_filter functi... |
| CVE-2026-34463 | HIGH | 8.6 | 0.4% | May 19, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerabil... |
| CVE-2026-34390 | MEDIUM | 5.1 | 0.4% | May 19, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vul... |
| CVE-2026-34358 | HIGH | 8.1 | 0.3% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access contr... |
| CVE-2026-34246 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc... |
| CVE-2026-34241 | HIGH | 8.7 | 0.3% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc... |
| CVE-2026-34234 | CRITICAL | 10 | 0.8% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p... |
| CVE-2026-39250 | HIGH | 7.3 | 0.2% | May 19, 2026 | An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly acces... |
| CVE-2026-34233 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers... |
| CVE-2026-34216 | MEDIUM | 6.6 | 0.5% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update ... |
| CVE-2026-32882 | HIGH | 7.1 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in... |
| CVE-2026-32814 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid imag... |
| CVE-2026-32741 | HIGH | 7.1 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in ... |
| CVE-2026-42526 | MEDIUM | 5.3 | 0.4% | May 19, 2026 | In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0... |
| CVE-2026-32740 | HIGH | 8.8 | 0.5% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (wr... |
| CVE-2026-32739 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequen... |
| CVE-2026-27173 | HIGH | 8.7 | 0.2% | May 19, 2026 | JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kube... |
| CVE-2026-8370 | HIGH | 8.5 | 0.1% | May 19, 2026 | Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power ... |
| CVE-2026-8096 | MEDIUM | 6.5 | 0.4% | May 19, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa... |
| CVE-2026-8073 | HIGH | 7.5 | 0.6% | May 19, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file del... |
| CVE-2026-41470 | HIGH | 8.2 | 0.5% | May 19, 2026 | LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at... |
| CVE-2026-34154 | MEDIUM | 5.3 | 0.2% | May 19, 2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1... |
| CVE-2026-33741 | MEDIUM | 6.8 | 0.2% | May 19, 2026 | EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use... |
| CVE-2026-33642 | CRITICAL | 9.8 | 0.3% | May 19, 2026 | Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now