2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41615 | HIGH | 7.4 | 0.6% | May 14, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to... |
| CVE-2026-7805 | — | — | — | May 14, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-3258. Reason: This candidate is a r... |
| CVE-2026-6923 | LOW | 3.8 | 0.1% | May 14, 2026 | A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie... |
| CVE-2026-45448 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | CWE-601 URL redirection to untrusted site ('open redirect') |
| CVE-2026-44827 | HIGH | 8.8 | 0.6% | May 14, 2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execut... |
| CVE-2026-44516 | HIGH | 7.6 | 0.2% | May 14, 2026 | Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClien... |
| CVE-2026-44515 | LOW | 2.3 | 0.2% | May 14, 2026 | Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feed... |
| CVE-2026-44514 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoi... |
| CVE-2026-44513 | HIGH | 8.8 | 1.1% | May 14, 2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPip... |
| CVE-2026-44511 | HIGH | 7.4 | 0.2% | May 14, 2026 | Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies wer... |
| CVE-2026-44348 | LOW | 2.5 | 0.1% | May 14, 2026 | PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha... |
| CVE-2026-44312 | MEDIUM | 5.8 | 0.1% | May 14, 2026 | css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allo... |
| CVE-2026-42555 | CRITICAL | 9.1 | 0.6% | May 14, 2026 | Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32... |
| CVE-2026-20224 | HIGH | 8.6 | 0.7% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated,... |
| CVE-2026-20210 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r... |
| CVE-2026-20209 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r... |
| CVE-2026-20182 | CRITICAL | 10 | 87.7% | May 14, 2026 | May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fi... |
| CVE-2026-44504 | HIGH | 8.6 | 0.3% | May 14, 2026 | Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared ... |
| CVE-2026-44503 | HIGH | 7 | 0.5% | May 14, 2026 | The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and othe... |
| CVE-2026-44501 | HIGH | 7.1 | 0.1% | May 14, 2026 | DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize... |
| CVE-2026-42597 | MEDIUM | 5.9 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/c... |
| CVE-2026-42596 | CRITICAL | 9.4 | 0.4% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's d... |
| CVE-2026-42595 | HIGH | 8.6 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/f... |
| CVE-2026-42594 | HIGH | 7.5 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine th... |
| CVE-2026-42593 | MEDIUM | 5.3 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoff... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now