2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23820 | HIGH | 7.2 | 0.6% | May 12, 2026 | A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authentic... |
| CVE-2026-23819 | HIGH | 8.8 | 0.3% | May 12, 2026 | A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u... |
| CVE-2026-5146 | MEDIUM | 4.3 | 0.2% | May 12, 2026 | Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacke... |
| CVE-2026-44343 | CRITICAL | 9.8 | 0.4% | May 12, 2026 | WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard t... |
| CVE-2026-44279 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, Forti... |
| CVE-2026-44278 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindo... |
| CVE-2026-44277 | CRITICAL | 9.8 | 0.6% | May 12, 2026 | A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticat... |
| CVE-2026-44204 | MEDIUM | 6.5 | 0.2% | May 12, 2026 | Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortB... |
| CVE-2026-44196 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication... |
| CVE-2026-44184 | HIGH | 8 | 0.1% | May 12, 2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c... |
| CVE-2026-44183 | CRITICAL | 9.8 | 0.2% | May 12, 2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c... |
| CVE-2026-44167 | HIGH | 7.5 | 0.2% | May 12, 2026 | phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 fil... |
| CVE-2026-44166 | HIGH | 7.6 | 0.2% | May 12, 2026 | Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker ... |
| CVE-2026-43929 | HIGH | 8.2 | 0.2% | May 12, 2026 | ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails t... |
| CVE-2026-43892 | HIGH | 8.8 | 0.3% | May 12, 2026 | AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli... |
| CVE-2026-43891 | HIGH | 7.5 | 0.4% | May 12, 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by... |
| CVE-2026-42899 | HIGH | 7.5 | 2.4% | May 12, 2026 | Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service o... |
| CVE-2026-42898 | CRITICAL | 9.9 | 1.2% | May 12, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a... |
| CVE-2026-42896 | HIGH | 7.8 | 0.3% | May 12, 2026 | Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2026-42893 | HIGH | 7.5 | 0.4% | May 12, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-42891 | MEDIUM | 6.5 | 0.3% | May 12, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-42838 | MEDIUM | 5.4 | 0.2% | May 12, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Ch... |
| CVE-2026-42833 | CRITICAL | 9.1 | 0.7% | May 12, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized a... |
| CVE-2026-42832 | MEDIUM | 5.5 | 0.2% | May 12, 2026 | Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
| CVE-2026-42831 | HIGH | 7.8 | 0.4% | May 12, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now