2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44855 | HIGH | 7.2 | 0.4% | May 12, 2026 | Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t... |
| CVE-2026-44854 | HIGH | 7.2 | 1.0% | May 12, 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc... |
| CVE-2026-44853 | HIGH | 7.2 | 1.0% | May 12, 2026 | Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc... |
| CVE-2026-44852 | HIGH | 7.2 | 0.4% | May 12, 2026 | An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vu... |
| CVE-2026-44225 | CRITICAL | 9.3 | 0.4% | May 12, 2026 | Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.... |
| CVE-2026-44223 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidd... |
| CVE-2026-44222 | HIGH | 7.5 | 0.4% | May 12, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Toke... |
| CVE-2026-44221 | CRITICAL | 9 | 0.3% | May 12, 2026 | ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 and prior to version 26.4.2, authenticated users and API tok... |
| CVE-2026-44220 | LOW | 3.2 | 0.2% | May 12, 2026 | ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 to 0.8.1 , the discover_pipeline_files() function i... |
| CVE-2026-44219 | LOW | 3.7 | 0.3% | May 12, 2026 | ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyz... |
| CVE-2026-44218 | LOW | 3 | 0.1% | May 12, 2026 | ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard con... |
| CVE-2026-44217 | MEDIUM | 6.6 | 0.4% | May 12, 2026 | sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, impl... |
| CVE-2026-44215 | HIGH | 7.1 | 0.2% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a one-byte heap out-of-bounds null write e... |
| CVE-2026-42889 | CRITICAL | 9.1 | 0.4% | May 12, 2026 | Relay adds real-time collaboration to Obsidian. Relay Server versions 0.9.0 through 0.9.6 contain an authentication bypa... |
| CVE-2026-42446 | HIGH | 7.1 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a stack-based out-of-bounds read exists in... |
| CVE-2026-42445 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability ex... |
| CVE-2026-42444 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists i... |
| CVE-2026-42443 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UF... |
| CVE-2026-42442 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the U... |
| CVE-2026-42355 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability ex... |
| CVE-2026-42338 | MEDIUM | 6.1 | 0.5% | May 12, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.gr... |
| CVE-2026-42191 | HIGH | 7.8 | 0.1% | May 12, 2026 | OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to... |
| CVE-2026-34690 | HIGH | 7.8 | 0.5% | May 12, 2026 | After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution i... |
| CVE-2026-34688 | MEDIUM | 6.2 | 0.3% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34686 | HIGH | 8.7 | 0.4% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a s... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now