2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28904 | HIGH | 7.5 | 0.4% | May 11, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,... |
| CVE-2026-28903 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,... |
| CVE-2026-28902 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, mac... |
| CVE-2026-28901 | MEDIUM | 4.3 | 0.4% | May 11, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, mac... |
| CVE-2026-28897 | MEDIUM | 6.2 | 0.2% | May 11, 2026 | A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS... |
| CVE-2026-28883 | HIGH | 7.5 | 0.4% | May 11, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and i... |
| CVE-2026-28873 | HIGH | 7.5 | 0.3% | May 11, 2026 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26... |
| CVE-2026-28872 | HIGH | 7.5 | 0.5% | May 11, 2026 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 1... |
| CVE-2026-28860 | HIGH | 7.5 | 0.4% | May 11, 2026 | The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 an... |
| CVE-2026-28848 | HIGH | 7.5 | 0.5% | May 11, 2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe ... |
| CVE-2026-28847 | HIGH | 8.8 | 0.6% | May 11, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,... |
| CVE-2026-28846 | HIGH | 7.5 | 0.7% | May 11, 2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS ... |
| CVE-2026-28840 | HIGH | 7.8 | 0.1% | May 11, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom... |
| CVE-2026-28830 | MEDIUM | 4.7 | 0.1% | May 11, 2026 | A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able t... |
| CVE-2026-28819 | MEDIUM | 5.4 | 7.1% | May 11, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1... |
| CVE-2026-20696 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS ... |
| CVE-2026-8321 | HIGH | 7.3 | 0.4% | May 11, 2026 | A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the f... |
| CVE-2026-8320 | MEDIUM | 4.7 | 0.2% | May 11, 2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode... |
| CVE-2026-8319 | MEDIUM | 5.5 | 0.4% | May 11, 2026 | A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this iss... |
| CVE-2026-6146 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores c... |
| CVE-2026-45026 | MEDIUM | 6.8 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln... |
| CVE-2026-45025 | MEDIUM | 6.8 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln... |
| CVE-2026-42887 | MEDIUM | 4.5 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulne... |
| CVE-2026-42886 | MEDIUM | 4.9 | 0.3% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint dec... |
| CVE-2026-42885 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now