2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45494 | MEDIUM | 6.1 | 0.3% | May 18, 2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-45492 | MEDIUM | 5.4 | 0.3% | May 18, 2026 | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security featur... |
| CVE-2026-45230 | CRITICAL | 9.1 | 0.6% | May 18, 2026 | DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelet... |
| CVE-2026-42822 | CRITICAL | 10 | 0.5% | May 18, 2026 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges ove... |
| CVE-2026-32849 | MEDIUM | 5.7 | 0.1% | May 18, 2026 | NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/op... |
| CVE-2026-32848 | MEDIUM | 5.7 | 0.1% | May 18, 2026 | NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem... |
| CVE-2026-29965 | MEDIUM | 6.1 | 0.2% | May 18, 2026 | HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to ... |
| CVE-2026-29964 | MEDIUM | 6.1 | 0.2% | May 18, 2026 | HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to impro... |
| CVE-2026-29963 | HIGH | 7.5 | 0.6% | May 18, 2026 | HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /t... |
| CVE-2026-29962 | HIGH | 7.5 | 0.4% | May 18, 2026 | HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-suppli... |
| CVE-2026-8843 | MEDIUM | 6.5 | 0.4% | May 18, 2026 | Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to ins... |
| CVE-2026-45829 | CRITICAL | 10 | 12.4% | May 18, 2026 | A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un... |
| CVE-2026-41085 | HIGH | 8.8 | 0.3% | May 18, 2026 | Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an auth... |
| CVE-2026-38719 | MEDIUM | 6.2 | 0.1% | May 18, 2026 | OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specific... |
| CVE-2026-36438 | MEDIUM | 5.3 | 0.3% | May 18, 2026 | An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information ... |
| CVE-2026-20685 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addres... |
| CVE-2026-41949 | HIGH | 7.5 | 0.4% | May 18, 2026 | Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any a... |
| CVE-2026-41948 | CRITICAL | 9.4 | 0.5% | May 18, 2026 | Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate reque... |
| CVE-2026-41947 | CRITICAL | 9.3 | 0.5% | May 18, 2026 | Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set ... |
| CVE-2026-39079 | HIGH | 7.5 | 0.3% | May 18, 2026 | An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive info... |
| CVE-2026-26462 | HIGH | 7.3 | 0.3% | May 18, 2026 | Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration... |
| CVE-2026-42009 | HIGH | 7.5 | 1.3% | May 18, 2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) pac... |
| CVE-2026-8803 | MEDIUM | 6.3 | 0.2% | May 18, 2026 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file... |
| CVE-2026-7304 | CRITICAL | 9.8 | 0.6% | May 18, 2026 | SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-lo... |
| CVE-2026-7302 | CRITICAL | 9.1 | 0.4% | May 18, 2026 | SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now