2026 CVE Vulnerabilities
64,734 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46724 | MEDIUM | 5.9 | 0.4% | May 19, 2026 | The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer config... |
| CVE-2026-46723 | MEDIUM | 5.9 | 0.3% | May 19, 2026 | The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe... |
| CVE-2026-46722 | MEDIUM | 5.9 | 0.3% | May 19, 2026 | The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document place... |
| CVE-2026-46721 | MEDIUM | 6.9 | 0.4% | May 19, 2026 | The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on th... |
| CVE-2026-46586 | HIGH | 8.8 | 0.5% | May 19, 2026 | Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluate... |
| CVE-2026-45434 | CRITICAL | 9.8 | 22.9% | May 19, 2026 | Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution T... |
| CVE-2026-45187 | MEDIUM | 6.5 | 0.5% | May 19, 2026 | Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users... |
| CVE-2026-41919 | CRITICAL | 9.1 | 0.5% | May 19, 2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. Thi... |
| CVE-2026-35086 | MEDIUM | 6.5 | 0.5% | May 19, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue a... |
| CVE-2026-31986 | CRITICAL | 9.1 | 0.4% | May 19, 2026 | Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. U... |
| CVE-2026-31910 | HIGH | 7.5 | 0.5% | May 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Us... |
| CVE-2026-31909 | HIGH | 7.5 | 0.5% | May 19, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFB... |
| CVE-2026-31906 | MEDIUM | 6.1 | 0.4% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. Thi... |
| CVE-2026-31388 | MEDIUM | 5.3 | 0.4% | May 19, 2026 | Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: bef... |
| CVE-2026-31387 | MEDIUM | 5.3 | 0.5% | May 19, 2026 | Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec... |
| CVE-2026-31380 | MEDIUM | 6.5 | 0.5% | May 19, 2026 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v... |
| CVE-2026-31379 | MEDIUM | 6.1 | 0.6% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname ... |
| CVE-2026-31378 | MEDIUM | 6.5 | 0.6% | May 19, 2026 | Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r... |
| CVE-2026-2611 | CRITICAL | 9.6 | 0.4% | May 19, 2026 | In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. ... |
| CVE-2026-29226 | HIGH | 7.3 | 0.5% | May 19, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects A... |
| CVE-2026-29220 | MEDIUM | 6.5 | 0.7% | May 19, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issu... |
| CVE-2026-29207 | MEDIUM | 6.5 | 0.5% | May 19, 2026 | Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects... |
| CVE-2026-44408 | MEDIUM | 6.3 | 0.3% | May 19, 2026 | There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an... |
| CVE-2026-8922 | MEDIUM | 5.4 | 0.3% | May 19, 2026 | A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Key... |
| CVE-2026-4885 | CRITICAL | 9.8 | 1.0% | May 19, 2026 | The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file typ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now