2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41486 | HIGH | 8.8 | 0.5% | May 8, 2026 | Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ... |
| CVE-2026-44400 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile ... |
| CVE-2026-7807 | HIGH | 8.8 | 0.3% | May 8, 2026 | SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary... |
| CVE-2026-44694 | CRITICAL | 9.1 | 0.2% | May 8, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From ... |
| CVE-2026-42282 | MEDIUM | 4.3 | 0.3% | May 8, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-42190 | MEDIUM | 5.3 | 0.1% | May 8, 2026 | RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsd... |
| CVE-2026-42189 | HIGH | 7.5 | 0.5% | May 8, 2026 | Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerabili... |
| CVE-2026-42185 | MEDIUM | 5.5 | 0.3% | May 8, 2026 | People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0,... |
| CVE-2026-42181 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-suppli... |
| CVE-2026-42180 | MEDIUM | 6.3 | 0.2% | May 8, 2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-priv... |
| CVE-2026-42176 | MEDIUM | 6.7 | 0.2% | May 8, 2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configurat... |
| CVE-2026-42160 | CRITICAL | 10 | 0.2% | May 8, 2026 | Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F... |
| CVE-2026-41495 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-8178 | CRITICAL | 9.2 | 0.6% | May 8, 2026 | An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load ... |
| CVE-2026-41511 | MEDIUM | 5.5 | 0.2% | May 8, 2026 | OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto... |
| CVE-2026-29203 | HIGH | 8.8 | 0.5% | May 8, 2026 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on ... |
| CVE-2026-29202 | HIGH | 8.8 | 0.8% | May 8, 2026 | Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution... |
| CVE-2026-29201 | HIGH | 8.6 | 0.4% | May 8, 2026 | Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f... |
| CVE-2026-6659 | HIGH | 7.5 | 0.4% | May 8, 2026 | Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function ... |
| CVE-2026-42072 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and wri... |
| CVE-2026-42030 | MEDIUM | 6.1 | 0.2% | May 8, 2026 | MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected X... |
| CVE-2026-42028 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGa... |
| CVE-2026-41889 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simp... |
| CVE-2026-41887 | MEDIUM | 4.9 | 0.4% | May 8, 2026 | Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restric... |
| CVE-2026-38360 | CRITICAL | 9.8 | 6.0% | May 8, 2026 | Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now