2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42345 | HIGH | 7.7 | 0.2% | May 8, 2026 | FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa... |
| CVE-2026-42344 | MEDIUM | 6.3 | 0.1% | May 8, 2026 | FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa... |
| CVE-2026-42343 | MEDIUM | 6.3 | 0.3% | May 8, 2026 | FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insuffi... |
| CVE-2026-42339 | HIGH | 7.1 | 0.3% | May 8, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.1... |
| CVE-2026-42307 | MEDIUM | 4.4 | 0.8% | May 8, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists... |
| CVE-2026-42302 | CRITICAL | 9.8 | 0.7% | May 8, 2026 | FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of... |
| CVE-2026-42298 | CRITICAL | 9.8 | 0.5% | May 8, 2026 | Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Pu... |
| CVE-2026-42291 | MEDIUM | 6.8 | 0.2% | May 8, 2026 | SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoin... |
| CVE-2026-42224 | HIGH | 7.6 | 0.3% | May 8, 2026 | ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allow... |
| CVE-2026-41682 | MEDIUM | 6.9 | 0.3% | May 8, 2026 | pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnera... |
| CVE-2026-41520 | MEDIUM | 4.4 | 0.1% | May 8, 2026 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.... |
| CVE-2026-41432 | HIGH | 8.2 | 0.3% | May 8, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio... |
| CVE-2026-42287 | CRITICAL | 10 | 0.2% | May 8, 2026 | Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and u... |
| CVE-2026-42286 | HIGH | 8.4 | 0.2% | May 8, 2026 | Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin func... |
| CVE-2026-42213 | MEDIUM | 5.1 | 0.5% | May 8, 2026 | SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.... |
| CVE-2026-42212 | HIGH | 7.1 | 0.3% | May 8, 2026 | SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.... |
| CVE-2026-42209 | MEDIUM | 6.5 | 0.4% | May 8, 2026 | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with reta... |
| CVE-2026-42206 | MEDIUM | 5.7 | 0.2% | May 8, 2026 | Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and ... |
| CVE-2026-42205 | HIGH | 8.8 | 0.3% | May 8, 2026 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne... |
| CVE-2026-42202 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-... |
| CVE-2026-42199 | MEDIUM | 6.2 | 0.1% | May 8, 2026 | Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand... |
| CVE-2026-42195 | LOW | 3.4 | 0.2% | May 8, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts... |
| CVE-2026-42193 | CRITICAL | 9.1 | 0.1% | May 8, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accep... |
| CVE-2026-42192 | MEDIUM | 5.4 | 0.2% | May 8, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (X... |
| CVE-2026-41517 | NONE | 0 | 0.3% | May 8, 2026 | Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows at... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now