2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46360 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that lim... |
| CVE-2026-46359 | HIGH | 7.7 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated atta... |
| CVE-2026-45800 | HIGH | 8.7 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45622 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45616 | MEDIUM | 5.1 | 0.2% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45010 | CRITICAL | 9.3 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/... |
| CVE-2026-45009 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated... |
| CVE-2026-45008 | HIGH | 7 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INST... |
| CVE-2026-45007 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIs... |
| CVE-2026-44826 | HIGH | 7.5 | 0.2% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2... |
| CVE-2026-44719 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor... |
| CVE-2026-44718 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor... |
| CVE-2026-44366 | MEDIUM | 6.1 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1... |
| CVE-2026-46474 | HIGH | 7.5 | 0.3% | May 15, 2026 | Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in ran... |
| CVE-2026-8695 | CRITICAL | 9.8 | 0.6% | May 15, 2026 | radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers t... |
| CVE-2026-46383 | MEDIUM | 5.5 | 0.6% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM conta... |
| CVE-2026-45539 | HIGH | 7.4 | 0.7% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive ... |
| CVE-2026-45038 | HIGH | 7.8 | 0.2% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape cont... |
| CVE-2026-45037 | HIGH | 7.1 | 0.1% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passe... |
| CVE-2026-45036 | HIGH | 7 | 0.1% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatical... |
| CVE-2026-45035 | HIGH | 8.8 | 0.4% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the ha... |
| CVE-2026-44774 | CRITICAL | 9.9 | 0.5% | May 15, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP... |
| CVE-2026-44717 | CRITICAL | 9.8 | 0.5% | May 15, 2026 | MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the ... |
| CVE-2026-44714 | HIGH | 7.5 | 0.3% | May 15, 2026 | The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends(... |
| CVE-2026-44699 | CRITICAL | 9.1 | 0.2% | May 15, 2026 | LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parame... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now