2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7814 | MEDIUM | 4.8 | 0.2% | May 11, 2026 | Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controll... |
| CVE-2026-7813 | CRITICAL | 9.9 | 0.5% | May 11, 2026 | Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Proces... |
| CVE-2026-6815 | MEDIUM | 5.9 | 0.5% | May 11, 2026 | An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path s... |
| CVE-2026-6093 | MEDIUM | 6 | 0.4% | May 11, 2026 | Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose record... |
| CVE-2026-44643 | CRITICAL | 10 | 0.5% | May 11, 2026 | Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to 1.5.2, an att... |
| CVE-2026-44201 | MEDIUM | 5.3 | 0.3% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and I... |
| CVE-2026-44200 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim... |
| CVE-2026-44199 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim... |
| CVE-2026-44198 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without ... |
| CVE-2026-44197 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without ... |
| CVE-2026-42841 | MEDIUM | 4.8 | 0.4% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject... |
| CVE-2026-42613 | CRITICAL | 9.4 | 0.9% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, the Login::register() method in the Login plugin accepts attac... |
| CVE-2026-42612 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/g... |
| CVE-2026-42611 | HIGH | 8.9 | 0.3% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can ... |
| CVE-2026-42610 | MEDIUM | 6.5 | 0.3% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.upda... |
| CVE-2026-42609 | HIGH | 8.1 | 0.5% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows ... |
| CVE-2026-42608 | CRITICAL | 9.1 | 0.5% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, there is a Path Traversal vulnerability within the FormFlash c... |
| CVE-2026-42607 | CRITICAL | 9.1 | 3.9% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achie... |
| CVE-2026-3320 | MEDIUM | 5.1 | 0.3% | May 11, 2026 | Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ... |
| CVE-2026-3319 | MEDIUM | 5.1 | 0.3% | May 11, 2026 | Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ... |
| CVE-2026-34092 | HIGH | 7.5 | 0.2% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-34091 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ... |
| CVE-2026-34090 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue ... |
| CVE-2026-34089 | HIGH | 7.5 | 0.2% | May 11, 2026 | Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2. |
| CVE-2026-34088 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now