2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44589 | LOW | 3.7 | 0.2% | May 14, 2026 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6.... |
| CVE-2026-44588 | CRITICAL | 9.4 | 0.5% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/... |
| CVE-2026-44586 | HIGH | 8.3 | 0.3% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace ... |
| CVE-2026-44523 | CRITICAL | 10 | 0.1% | May 14, 2026 | Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JW... |
| CVE-2026-44522 | HIGH | 8.6 | 0.5% | May 14, 2026 | Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows auth... |
| CVE-2026-41315 | CRITICAL | 9.8 | 1.0% | May 14, 2026 | mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command ex... |
| CVE-2026-38740 | MEDIUM | 5.3 | 0.1% | May 14, 2026 | Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The devi... |
| CVE-2026-27886 | HIGH | 7.5 | 0.6% | May 14, 2026 | Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did n... |
| CVE-2026-27680 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inj... |
| CVE-2026-23998 | HIGH | 7.5 | 0.2% | May 14, 2026 | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM managem... |
| CVE-2026-22707 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Con... |
| CVE-2026-22706 | MEDIUM | 6.5 | 0.3% | May 14, 2026 | Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a... |
| CVE-2026-22599 | HIGH | 7.2 | 1.2% | May 14, 2026 | Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.... |
| CVE-2026-6332 | HIGH | 7.5 | 0.1% | May 14, 2026 | CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive ... |
| CVE-2026-46470 | CRITICAL | 9.1 | 0.2% | May 14, 2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's ... |
| CVE-2026-46469 | MEDIUM | 5.5 | 0.1% | May 14, 2026 | An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's ... |
| CVE-2026-44544 | MEDIUM | 4.9 | 0.2% | May 14, 2026 | gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference S... |
| CVE-2026-44542 | CRITICAL | 9.1 | 0.5% | May 14, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-contr... |
| CVE-2026-44520 | MEDIUM | 5.7 | 0.2% | May 14, 2026 | Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit sema... |
| CVE-2026-44283 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulne... |
| CVE-2026-42897 | MEDIUM | 6.1 | 5.6% | May 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows... |
| CVE-2026-42598 | MEDIUM | 6.9 | 0.3% | May 14, 2026 | Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, t... |
| CVE-2026-42572 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a... |
| CVE-2026-42334 | HIGH | 7.5 | 0.3% | May 14, 2026 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22... |
| CVE-2026-41888 | MEDIUM | 6.5 | 0.3% | May 14, 2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELE... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now