2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44195 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler... |
| CVE-2026-44194 | CRITICAL | 9.1 | 6.4% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE)... |
| CVE-2026-44193 | CRITICAL | 9.1 | 0.7% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_se... |
| CVE-2026-42463 | HIGH | 8.1 | 0.2% | May 13, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cr... |
| CVE-2026-40328 | — | — | — | May 13, 2026 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2026-40327 | — | — | — | May 13, 2026 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2026-32993 | HIGH | 8.3 | 0.3% | May 13, 2026 | Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated a... |
| CVE-2026-32992 | HIGH | 8.2 | 0.3% | May 13, 2026 | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the... |
| CVE-2026-29205 | HIGH | 8.6 | 7.2% | May 13, 2026 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdav... |
| CVE-2026-8328 | MEDIUM | 5.9 | 0.5% | May 13, 2026 | The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to rep... |
| CVE-2026-45714 | CRITICAL | 9.1 | 0.4% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne... |
| CVE-2026-45708 | HIGH | 7.2 | 0.3% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php …... |
| CVE-2026-45229 | HIGH | 8.8 | 0.4% | May 13, 2026 | Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated... |
| CVE-2026-45228 | MEDIUM | 5.4 | 0.2% | May 13, 2026 | Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the... |
| CVE-2026-45055 | HIGH | 8.1 | 0.1% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the... |
| CVE-2026-45054 | MEDIUM | 4.9 | 0.2% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=ord... |
| CVE-2026-45053 | CRITICAL | 9.1 | 0.6% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Arbitrary File Upload vulnerability exists ... |
| CVE-2026-44418 | HIGH | 8.7 | 0.3% | May 13, 2026 | EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in ... |
| CVE-2026-44381 | MEDIUM | 5.3 | 0.2% | May 13, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed ... |
| CVE-2026-44380 | HIGH | 7.2 | 0.4% | May 13, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerabili... |
| CVE-2026-44379 | MEDIUM | 5.3 | 0.2% | May 13, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4... |
| CVE-2026-44377 | CRITICAL | 9.1 | 0.7% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an Authenticated Server-Side Template Injection (SSTI) vulne... |
| CVE-2026-44376 | MEDIUM | 6.1 | 0.7% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the... |
| CVE-2026-44373 | MEDIUM | 5.3 | 0.4% | May 13, 2026 | Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by send... |
| CVE-2026-44372 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now