2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44641 | HIGH | 7.1 | 0.4% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma... |
| CVE-2026-44310 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0... |
| CVE-2026-44309 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsi... |
| CVE-2026-42458 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-42207 | MEDIUM | 6.1 | 0.1% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-42155 | CRITICAL | 9.3 | 0.3% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-41258 | CRITICAL | 9.1 | 0.3% | May 15, 2026 | OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptRe... |
| CVE-2026-41181 | MEDIUM | 5.8 | 0.4% | May 15, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information di... |
| CVE-2026-23695 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in t... |
| CVE-2026-46508 | HIGH | 7.8 | 0.2% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo ... |
| CVE-2026-45803 | LOW | 3.5 | 0.2% | May 15, 2026 | `gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i... |
| CVE-2026-45773 | MEDIUM | 6.5 | 0.1% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-... |
| CVE-2026-45772 | CRITICAL | 9.8 | 0.4% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turbo... |
| CVE-2026-35194 | HIGH | 8.1 | 0.4% | May 15, 2026 | Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated u... |
| CVE-2026-2031 | CRITICAL | 10 | 0.5% | May 15, 2026 | An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prio... |
| CVE-2026-8669 | MEDIUM | 6.5 | 0.3% | May 15, 2026 | Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager:... |
| CVE-2026-46483 | HIGH | 7 | 0.6% | May 15, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu... |
| CVE-2026-45736 | HIGH | 7.5 | 0.7% | May 15, 2026 | ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is v... |
| CVE-2026-39054 | HIGH | 7.3 | 1.4% | May 15, 2026 | Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a she... |
| CVE-2026-39053 | MEDIUM | 6.5 | 0.4% | May 15, 2026 | Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-co... |
| CVE-2026-39052 | MEDIUM | 6.5 | 0.3% | May 15, 2026 | Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String express... |
| CVE-2026-38728 | HIGH | 7.5 | 0.6% | May 15, 2026 | An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStr... |
| CVE-2026-34253 | HIGH | 8.2 | 0.5% | May 15, 2026 | A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in functi... |
| CVE-2026-46333 | HIGH | 7.1 | 1.5% | May 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The ... |
| CVE-2026-7182 | CRITICAL | 9.2 | 0.4% | May 15, 2026 | Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now