2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33361 | HIGH | 7.5 | 0.2% | May 11, 2026 | In Meari IoT SDK image handling (libmrplayer.so) as observed in CloudEdge 5.5.0 (build 220), Arenti 1.8.1 (build 220), a... |
| CVE-2026-33359 | HIGH | 7.5 | 0.3% | May 11, 2026 | In Meari IoT Cloud alert image storage on Alibaba OSS (latest observed; storage service version not disclosed), motion s... |
| CVE-2026-33357 | HIGH | 7.5 | 0.2% | May 11, 2026 | In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and... |
| CVE-2026-33356 | HIGH | 7.7 | 0.3% | May 11, 2026 | In Meari IoT Cloud MQTT Broker deployments running EMQX 4.x, any authenticated low-privilege account can subscribe to gl... |
| CVE-2026-31254 | HIGH | 7.3 | 0.2% | May 11, 2026 | The flash-attention project thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains a code injection ... |
| CVE-2026-31253 | HIGH | 7.3 | 0.2% | May 11, 2026 | The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an ins... |
| CVE-2026-31252 | MEDIUM | 5.7 | 0.1% | May 11, 2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera... |
| CVE-2026-31251 | HIGH | 7.3 | 0.2% | May 11, 2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera... |
| CVE-2026-31250 | HIGH | 7.3 | 0.2% | May 11, 2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera... |
| CVE-2026-31249 | HIGH | 7.3 | 0.2% | May 11, 2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera... |
| CVE-2026-31248 | HIGH | 7.5 | 0.3% | May 11, 2026 | Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and val... |
| CVE-2026-8292 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A security vulnerability has been detected in Open5GS up to 2.7.7. The affected element is the function yuarel_parse in ... |
| CVE-2026-8291 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the fi... |
| CVE-2026-7820 | MEDIUM | 6.9 | 0.2% | May 11, 2026 | Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS o... |
| CVE-2026-7819 | HIGH | 8.1 | 0.4% | May 11, 2026 | Symbolic-link path traversal (CWE-61, CWE-22) in pgAdmin 4 File Manager. check_access_permission used os.path.abspath, ... |
| CVE-2026-7818 | HIGH | 7.8 | 0.1% | May 11, 2026 | Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe... |
| CVE-2026-7817 | HIGH | 7.1 | 0.2% | May 11, 2026 | Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration end... |
| CVE-2026-7816 | HIGH | 8.8 | 1.4% | May 11, 2026 | OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolat... |
| CVE-2026-7815 | HIGH | 8.8 | 0.5% | May 11, 2026 | SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_p... |
| CVE-2026-7814 | MEDIUM | 4.8 | 0.2% | May 11, 2026 | Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controll... |
| CVE-2026-7813 | CRITICAL | 9.9 | 0.5% | May 11, 2026 | Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Proces... |
| CVE-2026-6815 | MEDIUM | 5.9 | 0.5% | May 11, 2026 | An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path s... |
| CVE-2026-6093 | MEDIUM | 6 | 0.4% | May 11, 2026 | Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose record... |
| CVE-2026-44643 | CRITICAL | 10 | 0.5% | May 11, 2026 | Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an att... |
| CVE-2026-44201 | MEDIUM | 5.3 | 0.3% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and I... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now