2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30117 | CRITICAL | 9.8 | 0.5% | May 19, 2026 | scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parame... |
| CVE-2026-8711 | CRITICAL | 9.8 | 0.9% | May 19, 2026 | NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled... |
| CVE-2026-47100 | HIGH | 8.7 | 0.5% | May 19, 2026 | Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public c... |
| CVE-2026-45557 | MEDIUM | 6.9 | 0.4% | May 19, 2026 | Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in con... |
| CVE-2026-44159 | CRITICAL | 9.8 | 0.5% | May 19, 2026 | Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the c... |
| CVE-2026-43634 | HIGH | 8.7 | 0.2% | May 19, 2026 | HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers ... |
| CVE-2026-34883 | MEDIUM | 5.3 | 0.1% | May 19, 2026 | An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a ... |
| CVE-2026-2587 | CRITICAL | 9.6 | 0.6% | May 19, 2026 | A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used... |
| CVE-2026-2586 | CRITICAL | 9.1 | 0.8% | May 19, 2026 | An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user ... |
| CVE-2026-8975 | HIGH | 8.8 | 0.4% | May 19, 2026 | Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence... |
| CVE-2026-8974 | HIGH | 8.8 | 0.3% | May 19, 2026 | Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruptio... |
| CVE-2026-8973 | HIGH | 8.8 | 0.3% | May 19, 2026 | Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2026-8972 | HIGH | 8.8 | 0.3% | May 19, 2026 | Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 1... |
| CVE-2026-8971 | MEDIUM | 6.5 | 0.2% | May 19, 2026 | Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird ... |
| CVE-2026-8970 | HIGH | 8.8 | 0.3% | May 19, 2026 | Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunder... |
| CVE-2026-8969 | HIGH | 8.1 | 0.3% | May 19, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8968 | HIGH | 7.5 | 0.4% | May 19, 2026 | Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef... |
| CVE-2026-8967 | HIGH | 7.5 | 0.3% | May 19, 2026 | Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 15... |
| CVE-2026-8966 | HIGH | 7.5 | 0.3% | May 19, 2026 | Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8965 | HIGH | 7.5 | 0.3% | May 19, 2026 | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8964 | HIGH | 7.5 | 0.3% | May 19, 2026 | Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8963 | HIGH | 7.5 | 0.3% | May 19, 2026 | Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8962 | HIGH | 8.1 | 0.4% | May 19, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thund... |
| CVE-2026-8961 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderb... |
| CVE-2026-8960 | HIGH | 7.5 | 0.4% | May 19, 2026 | Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now