2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45362 | LOW | 3.2 | 0.1% | May 12, 2026 | Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file. |
| CVE-2026-45321 | CRITICAL | 9.6 | 2.3% | May 12, 2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were publ... |
| CVE-2026-8349 | MEDIUM | 4.3 | 0.3% | May 12, 2026 | A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Mes... |
| CVE-2026-8346 | HIGH | 8.8 | 3.1% | May 12, 2026 | A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing... |
| CVE-2026-8345 | HIGH | 8.8 | 3.2% | May 11, 2026 | A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the funct... |
| CVE-2026-43914 | CRITICAL | 9.8 | 0.3% | May 11, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaul... |
| CVE-2026-43913 | HIGH | 8.1 | 0.3% | May 11, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organiz... |
| CVE-2026-43912 | HIGH | 8.7 | 0.3% | May 11, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a group... |
| CVE-2026-43911 | HIGH | 8.1 | 0.2% | May 11, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when t... |
| CVE-2026-43901 | MEDIUM | 6.8 | 0.3% | May 11, 2026 | Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark... |
| CVE-2026-43900 | CRITICAL | 9.3 | 0.3% | May 11, 2026 | DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.... |
| CVE-2026-43899 | CRITICAL | 9.6 | 0.3% | May 11, 2026 | DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.... |
| CVE-2026-42554 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a rem... |
| CVE-2026-34963 | HIGH | 7.8 | 0.2% | May 11, 2026 | barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe... |
| CVE-2026-34962 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_... |
| CVE-2026-8344 | HIGH | 8.8 | 3.2% | May 11, 2026 | A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function ... |
| CVE-2026-7010 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. Th... |
| CVE-2026-44695 | MEDIUM | 6.5 | 0.1% | May 11, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET... |
| CVE-2026-43897 | HIGH | 8.7 | 0.4% | May 11, 2026 | Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. The... |
| CVE-2026-43893 | HIGH | 8.2 | 0.5% | May 11, 2026 | exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifToo... |
| CVE-2026-43890 | HIGH | 7.7 | 0.2% | May 11, 2026 | Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API end... |
| CVE-2026-43889 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both col... |
| CVE-2026-43888 | HIGH | 8.7 | 0.4% | May 11, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extract... |
| CVE-2026-43887 | HIGH | 7.3 | 0.2% | May 11, 2026 | Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section perm... |
| CVE-2026-43886 | HIGH | 8.2 | 0.2% | May 11, 2026 | Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now