2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44368 | MEDIUM | 6.9 | 0.3% | May 13, 2026 | PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implemen... |
| CVE-2026-42602 | HIGH | 8.1 | 0.2% | May 13, 2026 | azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in... |
| CVE-2026-42561 | HIGH | 7.5 | 0.7% | May 13, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service v... |
| CVE-2026-42304 | HIGH | 7.5 | 0.4% | May 13, 2026 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.n... |
| CVE-2026-39428 | MEDIUM | 4.8 | 0.2% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in ... |
| CVE-2026-39358 | HIGH | 7.2 | 0.3% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities... |
| CVE-2026-21821 | HIGH | 8.3 | 0.2% | May 13, 2026 | The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1... |
| CVE-2026-44364 | CRITICAL | 9.3 | 0.2% | May 13, 2026 | MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site... |
| CVE-2026-44363 | MEDIUM | 5.8 | 0.1% | May 13, 2026 | MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote r... |
| CVE-2026-44351 | CRITICAL | 9.1 | 0.2% | May 13, 2026 | fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerabili... |
| CVE-2026-42552 | HIGH | 7.5 | 0.3% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the ... |
| CVE-2026-42551 | HIGH | 7.5 | 0.3% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP... |
| CVE-2026-42550 | HIGH | 8.8 | 0.4% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePd... |
| CVE-2026-42549 | MEDIUM | 4.4 | 0.2% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recur... |
| CVE-2026-42548 | HIGH | 8.6 | 0.3% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query paramet... |
| CVE-2026-33381 | HIGH | 8.1 | 0.2% | May 13, 2026 | When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few ... |
| CVE-2026-33380 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's fi... |
| CVE-2026-33378 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the s... |
| CVE-2026-33377 | HIGH | 7.1 | 0.2% | May 13, 2026 | An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have wr... |
| CVE-2026-33376 | HIGH | 7.4 | 0.3% | May 13, 2026 | When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl... |
| CVE-2026-28383 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b... |
| CVE-2026-28380 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | Any Editor could delete any snapshot, even if they have no access to read or write them. |
| CVE-2026-28379 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur... |
| CVE-2026-28376 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req... |
| CVE-2026-28374 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now