2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32244 | MEDIUM | 5.3 | 0.2% | May 19, 2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1... |
| CVE-2026-30950 | HIGH | 7.1 | 0.4% | May 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-27964 | LOW | 3.9 | 0.1% | May 18, 2026 | FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-... |
| CVE-2026-27892 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores... |
| CVE-2026-27891 | HIGH | 7.2 | 0.5% | May 18, 2026 | FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerabi... |
| CVE-2026-27737 | MEDIUM | 6.5 | 0.3% | May 18, 2026 | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation for... |
| CVE-2026-8851 | HIGH | 8.6 | 0.3% | May 18, 2026 | SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionalit... |
| CVE-2026-8838 | CRITICAL | 9.8 | 0.8% | May 18, 2026 | Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver befor... |
| CVE-2026-4137 | HIGH | 7.8 | 0.2% | May 18, 2026 | In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` cr... |
| CVE-2026-27130 | CRITICAL | 9.9 | 1.0% | May 18, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection throu... |
| CVE-2026-26978 | HIGH | 8.6 | 0.9% | May 18, 2026 | FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize dat... |
| CVE-2026-25244 | CRITICAL | 9.8 | 2.8% | May 18, 2026 | WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appiu... |
| CVE-2026-22810 | HIGH | 7.3 | 0.2% | May 18, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior... |
| CVE-2026-47092 | HIGH | 7.8 | 0.5% | May 18, 2026 | Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attac... |
| CVE-2026-47091 | MEDIUM | 4.8 | 0.1% | May 18, 2026 | Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to r... |
| CVE-2026-47090 | MEDIUM | 4.6 | 0.1% | May 18, 2026 | Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd... |
| CVE-2026-45246 | MEDIUM | 6.8 | 0.1% | May 18, 2026 | Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite p... |
| CVE-2026-45245 | HIGH | 7.4 | 0.3% | May 18, 2026 | Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch ... |
| CVE-2026-45244 | MEDIUM | 5.4 | 0.2% | May 18, 2026 | Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automa... |
| CVE-2026-21789 | MEDIUM | 4.6 | 0.1% | May 18, 2026 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai... |
| CVE-2026-8836 | CRITICAL | 9.8 | 1.0% | May 18, 2026 | A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/sn... |
| CVE-2026-45243 | MEDIUM | 6.1 | 0.2% | May 18, 2026 | Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge... |
| CVE-2026-45242 | HIGH | 7.1 | 0.4% | May 18, 2026 | Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authe... |
| CVE-2026-45231 | MEDIUM | 6.1 | 0.2% | May 18, 2026 | DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, descripti... |
| CVE-2026-45495 | CRITICAL | 9.8 | 1.0% | May 18, 2026 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now