2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44427 | NONE | 0 | 0.4% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4... |
| CVE-2026-45781 | LOW | 3.5 | 0.2% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI... |
| CVE-2026-45370 | HIGH | 7.7 | 0.2% | May 14, 2026 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.p... |
| CVE-2026-45369 | HIGH | 8.3 | 0.3% | May 14, 2026 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_... |
| CVE-2026-44700 | HIGH | 8.7 | 0.3% | May 14, 2026 | Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certifica... |
| CVE-2026-44679 | MEDIUM | 6.9 | 0.3% | May 14, 2026 | Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticat... |
| CVE-2026-44678 | HIGH | 7.1 | 0.2% | May 14, 2026 | Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{... |
| CVE-2026-44673 | HIGH | 7.5 | 0.5% | May 14, 2026 | libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an ... |
| CVE-2026-44666 | CRITICAL | 9.3 | 0.3% | May 14, 2026 | HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeStri... |
| CVE-2026-44662 | MEDIUM | 5.1 | 0.2% | May 14, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::c... |
| CVE-2026-44661 | MEDIUM | 4.7 | 0.2% | May 14, 2026 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-S... |
| CVE-2026-44647 | HIGH | 7.1 | 0.3% | May 14, 2026 | OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected bou... |
| CVE-2026-44430 | MEDIUM | 4 | 0.3% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the... |
| CVE-2026-44429 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the... |
| CVE-2026-44212 | CRITICAL | 9.3 | 0.3% | May 14, 2026 | PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scriptin... |
| CVE-2026-42847 | HIGH | 7.1 | 0.2% | May 14, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi) ... |
| CVE-2026-42327 | HIGH | 8.7 | 0.2% | May 14, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_re... |
| CVE-2026-8634 | CRITICAL | 9.3 | 0.7% | May 14, 2026 | Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a ... |
| CVE-2026-8629 | HIGH | 8.6 | 0.3% | May 14, 2026 | Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only acc... |
| CVE-2026-8597 | HIGH | 7.2 | 0.4% | May 14, 2026 | Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 ... |
| CVE-2026-8596 | HIGH | 8.5 | 0.4% | May 14, 2026 | Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.... |
| CVE-2026-8587 | HIGH | 8.8 | 0.2% | May 14, 2026 | Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to... |
| CVE-2026-8586 | MEDIUM | 5.5 | 0.1% | May 14, 2026 | Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass d... |
| CVE-2026-8585 | HIGH | 7.5 | 0.2% | May 14, 2026 | Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had ... |
| CVE-2026-8584 | MEDIUM | 4.2 | 0.1% | May 14, 2026 | Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now