2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44258 | CRITICAL | 9.3 | 0.3% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targe... |
| CVE-2026-44257 | CRITICAL | 9.3 | 0.3% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, efw.file.FileManager.unZip writes zip entries to disk usin... |
| CVE-2026-44242 | LOW | 3.7 | 0.2% | May 12, 2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat... |
| CVE-2026-44241 | HIGH | 7.5 | 0.4% | May 12, 2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat... |
| CVE-2026-44015 | CRITICAL | 9.9 | 0.3% | May 12, 2026 | Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Serve... |
| CVE-2026-43948 | CRITICAL | 9.9 | 0.4% | May 12, 2026 | wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_... |
| CVE-2026-42855 | HIGH | 7.5 | 0.4% | May 12, 2026 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr... |
| CVE-2026-42854 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Pr... |
| CVE-2026-42844 | HIGH | 8.8 | 0.3% | May 12, 2026 | Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write ca... |
| CVE-2026-42545 | MEDIUM | 5.9 | 0.2% | May 12, 2026 | Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI ap... |
| CVE-2026-42544 | HIGH | 7.5 | 0.3% | May 12, 2026 | Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unau... |
| CVE-2026-42268 | HIGH | 7.5 | 0.4% | May 12, 2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.... |
| CVE-2026-42196 | CRITICAL | 9.9 | 0.6% | May 12, 2026 | django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerabl... |
| CVE-2026-41195 | MEDIUM | 5 | 0.2% | May 12, 2026 | mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package sourc... |
| CVE-2026-40902 | HIGH | 7.5 | 0.4% | May 12, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, ... |
| CVE-2026-40863 | HIGH | 7.5 | 0.4% | May 12, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, ... |
| CVE-2026-35555 | HIGH | 7 | 0.2% | May 12, 2026 | PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an... |
| CVE-2026-33570 | MEDIUM | 6.9 | 0.2% | May 12, 2026 | PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normall... |
| CVE-2026-26289 | HIGH | 8.4 | 0.1% | May 12, 2026 | PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to ... |
| CVE-2026-44403 | HIGH | 8.6 | 2.6% | May 12, 2026 | Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization ... |
| CVE-2026-44246 | HIGH | 7.2 | 0.2% | May 12, 2026 | nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nn... |
| CVE-2026-44240 | HIGH | 7.5 | 0.5% | May 12, 2026 | basic-ftp is an FTP client for Node.js. Prior to 5.3.1, basic-ftp is vulnerable to client-side denial of service when pa... |
| CVE-2026-44232 | HIGH | 8.7 | 0.3% | May 12, 2026 | DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.3, eve... |
| CVE-2026-44224 | HIGH | 8.8 | 0.4% | May 12, 2026 | Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbi... |
| CVE-2026-44012 | HIGH | 7.1 | 0.3% | May 12, 2026 | Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now