2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33637 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 ... |
| CVE-2026-32738 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequen... |
| CVE-2026-8605 | CRITICAL | 9.8 | 0.4% | May 19, 2026 | In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA syst... |
| CVE-2026-8604 | HIGH | 8.8 | 0.2% | May 19, 2026 | In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a vic... |
| CVE-2026-8603 | CRITICAL | 9.8 | 1.3% | May 19, 2026 | In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on t... |
| CVE-2026-8602 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at... |
| CVE-2026-6009 | HIGH | 8.7 | 0.5% | May 19, 2026 | Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allow... |
| CVE-2026-47107 | HIGH | 8.6 | 0.2% | May 19, 2026 | Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files ... |
| CVE-2026-33633 | HIGH | 8.8 | 0.4% | May 19, 2026 | Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_dat... |
| CVE-2026-32134 | MEDIUM | 5.9 | 0.4% | May 19, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles... |
| CVE-2026-5511 | LOW | 2.7 | 0.2% | May 19, 2026 | In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i... |
| CVE-2026-47358 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded... |
| CVE-2026-47357 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem... |
| CVE-2026-47356 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the fi... |
| CVE-2026-36829 | CRITICAL | 9.8 | 1.3% | May 19, 2026 | An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7.... |
| CVE-2026-36828 | HIGH | 8.8 | 1.7% | May 19, 2026 | A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and includin... |
| CVE-2026-36827 | MEDIUM | 5.4 | 0.7% | May 19, 2026 | A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface inv... |
| CVE-2026-8706 | MEDIUM | 6.5 | 0.2% | May 19, 2026 | Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same devi... |
| CVE-2026-5804 | HIGH | 8.4 | 0.2% | May 19, 2026 | An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). T... |
| CVE-2026-37281 | CRITICAL | 9.8 | 1.6% | May 19, 2026 | An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remo... |
| CVE-2026-31072 | CRITICAL | 9.8 | 0.8% | May 19, 2026 | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remot... |
| CVE-2026-31071 | CRITICAL | 9.1 | 0.5% | May 19, 2026 | API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated... |
| CVE-2026-31070 | CRITICAL | 9.8 | 0.5% | May 19, 2026 | The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileg... |
| CVE-2026-31069 | HIGH | 8.8 | 0.4% | May 19, 2026 | BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlle... |
| CVE-2026-30118 | CRITICAL | 9.8 | 0.5% | May 19, 2026 | scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now