2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8207 | HIGH | 7 | 0.2% | May 9, 2026 | Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr... |
| CVE-2026-7652 | MEDIUM | 5.3 | 0.7% | May 9, 2026 | The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthe... |
| CVE-2026-6667 | MEDIUM | 4.3 | 0.3% | May 9, 2026 | PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users ... |
| CVE-2026-6666 | HIGH | 7.5 | 0.4% | May 9, 2026 | A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response ... |
| CVE-2026-6665 | CRITICAL | 9.8 | 0.4% | May 9, 2026 | The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the conten... |
| CVE-2026-6664 | HIGH | 7.5 | 0.7% | May 9, 2026 | An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to ... |
| CVE-2026-41705 | HIGH | 8.6 | 0.4% | May 9, 2026 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized... |
| CVE-2026-44313 | CRITICAL | 9.1 | 0.3% | May 9, 2026 | Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior... |
| CVE-2026-42455 | HIGH | 8.8 | 0.5% | May 9, 2026 | Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve... |
| CVE-2026-45130 | MEDIUM | 5.5 | 0.2% | May 8, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compou... |
| CVE-2026-44987 | LOW | 3.8 | 0.2% | May 8, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissi... |
| CVE-2026-44656 | MEDIUM | 5.3 | 0.9% | May 8, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists... |
| CVE-2026-44286 | LOW | 2.3 | 0.2% | May 8, 2026 | FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF... |
| CVE-2026-44284 | MEDIUM | 6.3 | 0.2% | May 8, 2026 | FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in M... |
| CVE-2026-42556 | CRITICAL | 9 | 0.3% | May 8, 2026 | Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who c... |
| CVE-2026-42456 | MEDIUM | 4.3 | 0.3% | May 8, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-42454 | CRITICAL | 9.9 | 0.7% | May 8, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-42453 | HIGH | 8.7 | 1.2% | May 8, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-42452 | HIGH | 8.1 | 0.3% | May 8, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-42451 | MEDIUM | 6.3 | 0.1% | May 8, 2026 | Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in ... |
| CVE-2026-42354 | CRITICAL | 9.8 | 0.6% | May 8, 2026 | Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical v... |
| CVE-2026-42352 | HIGH | 8.6 | 0.5% | May 8, 2026 | pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23... |
| CVE-2026-42351 | HIGH | 7.5 | 0.5% | May 8, 2026 | pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23... |
| CVE-2026-42350 | MEDIUM | 5.1 | 0.2% | May 8, 2026 | Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Ka... |
| CVE-2026-42346 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now