2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8959 | CRITICAL | 9.6 | 0.4% | May 19, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire... |
| CVE-2026-8958 | HIGH | 8.6 | 0.3% | May 19, 2026 | Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi... |
| CVE-2026-8957 | HIGH | 8.8 | 0.4% | May 19, 2026 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.... |
| CVE-2026-8956 | CRITICAL | 9.8 | 0.6% | May 19, 2026 | Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thun... |
| CVE-2026-8955 | HIGH | 8.8 | 0.4% | May 19, 2026 | Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thu... |
| CVE-2026-8954 | HIGH | 7.5 | 0.4% | May 19, 2026 | Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 15... |
| CVE-2026-8953 | CRITICAL | 9.6 | 0.5% | May 19, 2026 | Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 15... |
| CVE-2026-8952 | HIGH | 8.8 | 0.4% | May 19, 2026 | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 15... |
| CVE-2026-8951 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151. |
| CVE-2026-8950 | CRITICAL | 9.3 | 0.2% | May 19, 2026 | Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 14... |
| CVE-2026-8949 | HIGH | 7.5 | 0.6% | May 19, 2026 | Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunde... |
| CVE-2026-8948 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird ... |
| CVE-2026-8947 | HIGH | 7.3 | 0.4% | May 19, 2026 | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36,... |
| CVE-2026-8946 | HIGH | 7.5 | 0.6% | May 19, 2026 | Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Fir... |
| CVE-2026-8945 | HIGH | 7.5 | 0.4% | May 19, 2026 | Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151. |
| CVE-2026-6354 | — | — | — | May 19, 2026 | Rejected reason: Voluntarily withdrawn |
| CVE-2026-47323 | CRITICAL | 9.8 | 1.4% | May 19, 2026 | Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStra... |
| CVE-2026-43633 | CRITICAL | 10 | 1.1% | May 19, 2026 | HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a ... |
| CVE-2026-42100 | HIGH | 7.5 | 0.7% | May 19, 2026 | Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to ... |
| CVE-2026-42099 | HIGH | 7.5 | 0.7% | May 19, 2026 | Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The applica... |
| CVE-2026-42098 | HIGH | 8.7 | 0.4% | May 19, 2026 | Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An... |
| CVE-2026-42097 | HIGH | 8.8 | 0.9% | May 19, 2026 | Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter ... |
| CVE-2026-42096 | HIGH | 8.8 | 0.6% | May 19, 2026 | Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per... |
| CVE-2026-23558 | HIGH | 7.8 | 0.1% | May 19, 2026 | The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or ... |
| CVE-2026-23557 | MEDIUM | 6.5 | 0.2% | May 19, 2026 | Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now