2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42884 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/col... |
| CVE-2026-42883 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpo... |
| CVE-2026-42882 | CRITICAL | 9.4 | 0.6% | May 11, 2026 | oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused ... |
| CVE-2026-42876 | MEDIUM | 4.9 | 0.2% | May 11, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-42875 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-42874 | LOW | 3.7 | 0.2% | May 11, 2026 | Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its ... |
| CVE-2026-42873 | NONE | 0 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with m... |
| CVE-2026-42872 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) v... |
| CVE-2026-42870 | MEDIUM | 6.4 | 0.3% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw... |
| CVE-2026-42869 | CRITICAL | 10 | 0.4% | May 11, 2026 | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,... |
| CVE-2026-42565 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | @workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec... |
| CVE-2026-42050 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9... |
| CVE-2026-36734 | HIGH | 8.8 | 1.0% | May 11, 2026 | EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can su... |
| CVE-2026-2614 | HIGH | 7.5 | 2.9% | May 11, 2026 | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 ... |
| CVE-2026-8318 | MEDIUM | 5.5 | 0.4% | May 11, 2026 | A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by t... |
| CVE-2026-7790 | HIGH | 7.5 | 0.4% | May 11, 2026 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. T... |
| CVE-2026-45224 | HIGH | 7.1 | 0.1% | May 11, 2026 | Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allow... |
| CVE-2026-45223 | HIGH | 8.8 | 0.4% | May 11, 2026 | Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path whe... |
| CVE-2026-45222 | MEDIUM | 6.9 | 0.1% | May 11, 2026 | Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with def... |
| CVE-2026-43969 | LOW | 3.2 | 0.1% | May 11, 2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split... |
| CVE-2026-43968 | MEDIUM | 4 | 0.2% | May 11, 2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splittin... |
| CVE-2026-42871 | MEDIUM | 6.9 | 0.3% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displa... |
| CVE-2026-42866 | MEDIUM | 6.7 | 0.1% | May 11, 2026 | Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write... |
| CVE-2026-42864 | CRITICAL | 9.9 | 0.3% | May 11, 2026 | FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint ... |
| CVE-2026-8305 | CRITICAL | 9.8 | 0.6% | May 11, 2026 | A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookR... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now