2026 CVE Vulnerabilities
64,732 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42096 | HIGH | 8.8 | 0.6% | May 19, 2026 | Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per... |
| CVE-2026-23558 | HIGH | 7.8 | 0.1% | May 19, 2026 | The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or ... |
| CVE-2026-23557 | MEDIUM | 6.5 | 0.2% | May 19, 2026 | Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri... |
| CVE-2026-8912 | HIGH | 7.5 | 0.4% | May 19, 2026 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to... |
| CVE-2026-4883 | CRITICAL | 9.8 | 0.8% | May 19, 2026 | The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the... |
| CVE-2026-7860 | LOW | 1.6 | 0.1% | May 19, 2026 | A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes ... |
| CVE-2026-7571 | HIGH | 7.1 | 0.3% | May 19, 2026 | A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a secur... |
| CVE-2026-7507 | HIGH | 7.5 | 0.6% | May 19, 2026 | A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could expl... |
| CVE-2026-7504 | HIGH | 8.1 | 0.5% | May 19, 2026 | A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an atta... |
| CVE-2026-7307 | HIGH | 7.5 | 0.7% | May 19, 2026 | A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security ... |
| CVE-2026-4630 | MEDIUM | 6.8 | 0.3% | May 19, 2026 | A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerabi... |
| CVE-2026-45442 | MEDIUM | 4.3 | 0.2% | May 19, 2026 | Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-43493 | CRITICAL | 9.8 | 0.6% | May 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG reques... |
| CVE-2026-43492 | MEDIUM | 5.5 | 0.1% | May 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_... |
| CVE-2026-43491 | MEDIUM | 5.5 | 0.1% | May 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registratio... |
| CVE-2026-37982 | MEDIUM | 6.8 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsAction... |
| CVE-2026-37981 | MEDIUM | 4.3 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows... |
| CVE-2026-37979 | MEDIUM | 6.5 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection ... |
| CVE-2026-37978 | MEDIUM | 4.9 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th... |
| CVE-2026-8827 | HIGH | 8.2 | 0.3% | May 19, 2026 | The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading ... |
| CVE-2026-8727 | HIGH | 7.1 | 0.4% | May 19, 2026 | The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An ... |
| CVE-2026-8726 | HIGH | 8.2 | 0.4% | May 19, 2026 | The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated... |
| CVE-2026-46725 | CRITICAL | 9.2 | 2.3% | May 19, 2026 | The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. ... |
| CVE-2026-46724 | MEDIUM | 5.9 | 0.4% | May 19, 2026 | The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer config... |
| CVE-2026-46723 | MEDIUM | 5.9 | 0.3% | May 19, 2026 | The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now