2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8194 | MEDIUM | 4.3 | 0.2% | May 9, 2026 | A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include... |
| CVE-2026-42606 | HIGH | 8.8 | 0.5% | May 9, 2026 | AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middlewa... |
| CVE-2026-42605 | HIGH | 8.8 | 0.8% | May 9, 2026 | AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request... |
| CVE-2026-42601 | CRITICAL | 9.8 | 0.4% | May 9, 2026 | ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddVi... |
| CVE-2026-42576 | MEDIUM | 6.5 | 0.3% | May 9, 2026 | apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKey... |
| CVE-2026-42575 | HIGH | 7.5 | 0.2% | May 9, 2026 | apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifi... |
| CVE-2026-42574 | HIGH | 7.5 | 0.4% | May 9, 2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before versi... |
| CVE-2026-42571 | CRITICAL | 9 | 0.3% | May 9, 2026 | Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.2... |
| CVE-2026-42569 | CRITICAL | 9.4 | 1.2% | May 9, 2026 | phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS a... |
| CVE-2026-42562 | HIGH | 8.3 | 0.3% | May 9, 2026 | Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to... |
| CVE-2026-42333 | MEDIUM | 6.3 | 0.4% | May 9, 2026 | Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to ve... |
| CVE-2026-42258 | MEDIUM | 5.3 | 0.8% | May 9, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5... |
| CVE-2026-42257 | CRITICAL | 9.8 | 0.4% | May 9, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5... |
| CVE-2026-42256 | MEDIUM | 6.5 | 0.3% | May 9, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before... |
| CVE-2026-42246 | HIGH | 7.4 | 0.3% | May 9, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4... |
| CVE-2026-42245 | HIGH | 7.5 | 0.4% | May 9, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5... |
| CVE-2026-41893 | HIGH | 7.5 | 0.3% | May 9, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login en... |
| CVE-2026-8193 | MEDIUM | 6.3 | 0.2% | May 9, 2026 | A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf... |
| CVE-2026-8192 | HIGH | 8.8 | 4.8% | May 9, 2026 | A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of t... |
| CVE-2026-8191 | HIGH | 8.8 | 5.3% | May 9, 2026 | A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-... |
| CVE-2026-8190 | HIGH | 8.8 | 5.3% | May 9, 2026 | A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file ... |
| CVE-2026-8189 | HIGH | 8.8 | 4.8% | May 9, 2026 | A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater o... |
| CVE-2026-8188 | HIGH | 8.8 | 5.5% | May 9, 2026 | A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the fi... |
| CVE-2026-8198 | MEDIUM | 5.3 | 0.4% | May 9, 2026 | The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to A... |
| CVE-2026-8186 | HIGH | 7.5 | 0.5% | May 9, 2026 | A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now