2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44659 | MEDIUM | 4.7 | 0.2% | May 11, 2026 | Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address b... |
| CVE-2026-44658 | LOW | 2.4 | 0.2% | May 11, 2026 | Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in... |
| CVE-2026-44413 | HIGH | 7.5 | 0.3% | May 11, 2026 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access |
| CVE-2026-44226 | MEDIUM | 5.3 | 0.3% | May 11, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns fu... |
| CVE-2026-43995 | CRITICAL | 9.8 | 0.4% | May 11, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool i... |
| CVE-2026-43896 | MEDIUM | 5.5 | 0.2% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a c... |
| CVE-2026-43895 | MEDIUM | 4.4 | 0.2% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-langu... |
| CVE-2026-43894 | MEDIUM | 5.5 | 0.2% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX... |
| CVE-2026-43640 | HIGH | 8.6 | 0.5% | May 11, 2026 | Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an or... |
| CVE-2026-43639 | CRITICAL | 9.1 | 0.6% | May 11, 2026 | Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user t... |
| CVE-2026-43638 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to... |
| CVE-2026-42865 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis... |
| CVE-2026-42860 | HIGH | 8.5 | 0.3% | May 11, 2026 | The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync... |
| CVE-2026-42859 | HIGH | 8.1 | 0.5% | May 11, 2026 | Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RS... |
| CVE-2026-42858 | CRITICAL | 9.9 | 0.4% | May 11, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in... |
| CVE-2026-42857 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_ht... |
| CVE-2026-42856 | HIGH | 8.7 | 0.5% | May 11, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC too... |
| CVE-2026-42316 | MEDIUM | 6.5 | 0.3% | May 11, 2026 | kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2... |
| CVE-2026-42315 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name... |
| CVE-2026-42314 | MEDIUM | 6.5 | 0.3% | May 11, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are s... |
| CVE-2026-42313 | HIGH | 8.3 | 0.4% | May 11, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API... |
| CVE-2026-42312 | MEDIUM | 6.8 | 0.2% | May 11, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API... |
| CVE-2026-41431 | HIGH | 8 | 0.2% | May 11, 2026 | Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mo... |
| CVE-2026-41257 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in... |
| CVE-2026-41256 | MEDIUM | 5.5 | 0.2% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncate... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now