2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34087 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue a... |
| CVE-2026-34086 | LOW | 2.1 | 0.2% | May 11, 2026 | Vulnerability in Wikimedia Foundation AbuseFilter. This issue affects AbuseFilter: from * before 1.43.7, 1.44.4, 1.45.2... |
| CVE-2026-31247 | HIGH | 7.5 | 0.4% | May 11, 2026 | Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse... |
| CVE-2026-31246 | MEDIUM | 6.5 | 0.7% | May 11, 2026 | GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (... |
| CVE-2026-8290 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A security flaw has been discovered in Open5GS up to 2.7.7. This issue affects the function smf_nsmf_handle_update_data_... |
| CVE-2026-8289 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A vulnerability was identified in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_update_da... |
| CVE-2026-4802 | HIGH | 8 | 1.0% | May 11, 2026 | A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the h... |
| CVE-2026-8288 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsm_handle_pdu_session_modification_qos... |
| CVE-2026-6956 | MEDIUM | 5.1 | 0.4% | May 11, 2026 | ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL ... |
| CVE-2026-6909 | MEDIUM | 5.1 | 0.4% | May 11, 2026 | ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL ... |
| CVE-2026-41951 | HIGH | 8.6 | 0.5% | May 11, 2026 | Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS te... |
| CVE-2026-40636 | HIGH | 7.8 | 0.2% | May 11, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded c... |
| CVE-2026-35157 | CRITICAL | 9.8 | 0.3% | May 11, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper neutraliz... |
| CVE-2026-32658 | HIGH | 8.8 | 0.2% | May 11, 2026 | Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged att... |
| CVE-2026-26946 | MEDIUM | 6.7 | 0.1% | May 11, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege... |
| CVE-2026-43826 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pa... |
| CVE-2026-41018 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user... |
| CVE-2026-5084 | MEDIUM | 6.5 | 0.3% | May 11, 2026 | WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates t... |
| CVE-2026-43500 | HIGH | 7.8 | 92.9% | May 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when page... |
| CVE-2026-8276 | LOW | 3.7 | 0.4% | May 11, 2026 | A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some unknown functionality of the file module... |
| CVE-2026-8275 | LOW | 3.7 | 0.5% | May 11, 2026 | A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBod... |
| CVE-2026-6433 | HIGH | 7.3 | 0.8% | May 11, 2026 | The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL quer... |
| CVE-2026-1677 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enable... |
| CVE-2026-8274 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of th... |
| CVE-2026-8273 | HIGH | 7.2 | 4.5% | May 11, 2026 | A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_con... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now