2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8043 | CRITICAL | 9.6 | 0.9% | May 12, 2026 | External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read... |
| CVE-2026-7432 | HIGH | 7 | 0.3% | May 12, 2026 | A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges... |
| CVE-2026-7431 | MEDIUM | 4.4 | 0.2% | May 12, 2026 | An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local a... |
| CVE-2026-6866 | HIGH | 7.5 | 0.3% | May 12, 2026 | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclo... |
| CVE-2026-5061 | MEDIUM | 4.7 | 0.1% | May 12, 2026 | The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper tha... |
| CVE-2026-43983 | HIGH | 8.1 | 0.2% | May 12, 2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th... |
| CVE-2026-43939 | HIGH | 7.3 | 0.2% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc... |
| CVE-2026-43938 | HIGH | 8.1 | 0.3% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE... |
| CVE-2026-43937 | HIGH | 8.8 | 0.5% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects... |
| CVE-2026-42260 | HIGH | 8.2 | 0.2% | May 12, 2026 | Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to ... |
| CVE-2026-32687 | HIGH | 7.8 | 0.2% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr... |
| CVE-2026-8391 | MEDIUM | 5.3 | 0.3% | May 12, 2026 | Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir... |
| CVE-2026-8390 | HIGH | 7.3 | 0.3% | May 12, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. |
| CVE-2026-8389 | HIGH | 8.8 | 0.3% | May 12, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. |
| CVE-2026-8388 | MEDIUM | 6.5 | 0.2% | May 12, 2026 | Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, ... |
| CVE-2026-6865 | HIGH | 7.1 | 0.3% | May 12, 2026 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause un... |
| CVE-2026-45091 | CRITICAL | 9.1 | 0.3% | May 12, 2026 | sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterp... |
| CVE-2026-43930 | MEDIUM | 5.9 | 0.2% | May 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 ... |
| CVE-2026-43916 | HIGH | 8.7 | 0.3% | May 12, 2026 | pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior... |
| CVE-2026-42006 | MEDIUM | 4.3 | 0.6% | May 12, 2026 | An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple... |
| CVE-2026-40638 | MEDIUM | 6.7 | 0.1% | May 12, 2026 | Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability... |
| CVE-2026-40020 | MEDIUM | 4.3 | 0.3% | May 12, 2026 | Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_all... |
| CVE-2026-40016 | MEDIUM | 6.5 | 0.3% | May 12, 2026 | Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits ... |
| CVE-2026-35071 | HIGH | 8.2 | 0.5% | May 12, 2026 | Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in... |
| CVE-2026-33603 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now