2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41932 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::... |
| CVE-2026-24712 | HIGH | 7.3 | 0.9% | May 14, 2026 | Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. |
| CVE-2026-24711 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. |
| CVE-2026-24710 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. |
| CVE-2026-21730 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unaut... |
| CVE-2026-6638 | HIGH | 8.8 | 0.2% | May 14, 2026 | SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre... |
| CVE-2026-6637 | HIGH | 8.8 | 0.4% | May 14, 2026 | Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th... |
| CVE-2026-6575 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau... |
| CVE-2026-6479 | HIGH | 7.5 | 0.5% | May 14, 2026 | Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX ... |
| CVE-2026-6478 | MEDIUM | 6.5 | 0.6% | May 14, 2026 | Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us... |
| CVE-2026-6477 | HIGH | 8.8 | 0.5% | May 14, 2026 | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee... |
| CVE-2026-6476 | HIGH | 7.2 | 0.3% | May 14, 2026 | SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra... |
| CVE-2026-6475 | HIGH | 8.8 | 0.3% | May 14, 2026 | Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca... |
| CVE-2026-6474 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server... |
| CVE-2026-6473 | HIGH | 8.8 | 1.0% | May 14, 2026 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un... |
| CVE-2026-6472 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to... |
| CVE-2026-1630 | MEDIUM | 5.1 | 0.4% | May 14, 2026 | WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can sen... |
| CVE-2026-6008 | MEDIUM | 6.8 | 0.2% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu... |
| CVE-2026-5798 | HIGH | 7.1 | 0.2% | May 14, 2026 | Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ en... |
| CVE-2026-5790 | MEDIUM | 5.1 | 0.3% | May 14, 2026 | Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via ... |
| CVE-2026-4031 | HIGH | 7.5 | 0.5% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ... |
| CVE-2026-4030 | HIGH | 8.1 | 0.5% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in... |
| CVE-2026-4029 | HIGH | 7.5 | 0.4% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up ... |
| CVE-2026-43644 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints wher... |
| CVE-2026-45205 | MEDIUM | 5.3 | 0.5% | May 14, 2026 | Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Config... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now