2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7301 | CRITICAL | 9.8 | 0.4% | May 18, 2026 | SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that cal... |
| CVE-2026-0983 | HIGH | 7.1 | 0.2% | May 18, 2026 | Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 all... |
| CVE-2026-8802 | MEDIUM | 5.3 | 0.4% | May 18, 2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function get... |
| CVE-2026-4320 | CRITICAL | 9.3 | 0.3% | May 18, 2026 | Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to pr... |
| CVE-2026-41119 | MEDIUM | 6.8 | 0.1% | May 18, 2026 | Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A rem... |
| CVE-2026-7498 | HIGH | 8.8 | 0.3% | May 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio... |
| CVE-2026-6902 | HIGH | 7.7 | 0.4% | May 18, 2026 | A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has ... |
| CVE-2026-6347 | HIGH | 7.6 | 0.3% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie... |
| CVE-2026-6346 | HIGH | 8.7 | 0.3% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie... |
| CVE-2026-6345 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user pass... |
| CVE-2026-6343 | MEDIUM | 4.3 | 0.2% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions whi... |
| CVE-2026-6339 | MEDIUM | 4.3 | 0.1% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read ... |
| CVE-2026-6333 | MEDIUM | 5 | 0.1% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response UR... |
| CVE-2026-5163 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites whic... |
| CVE-2026-4643 | LOW | 3.5 | 0.2% | May 18, 2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying ... |
| CVE-2026-4286 | MEDIUM | 4.3 | 0.1% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating p... |
| CVE-2026-3471 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in t... |
| CVE-2026-3117 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing comma... |
| CVE-2026-28732 | MEDIUM | 4.3 | 0.2% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word u... |
| CVE-2026-8788 | HIGH | 7.3 | 0.2% | May 18, 2026 | Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were n... |
| CVE-2026-6342 | MEDIUM | 4.3 | 0.2% | May 18, 2026 | Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allow... |
| CVE-2026-6341 | MEDIUM | 4.3 | 0.2% | May 18, 2026 | Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can c... |
| CVE-2026-6340 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure befo... |
| CVE-2026-6334 | LOW | 3.8 | 0.1% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth autho... |
| CVE-2026-4273 | MEDIUM | 4.3 | 0.1% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the orig... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now