2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41889 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simp... |
| CVE-2026-41887 | MEDIUM | 4.9 | 0.4% | May 8, 2026 | Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restric... |
| CVE-2026-38360 | CRITICAL | 9.8 | 6.0% | May 8, 2026 | Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut... |
| CVE-2026-44499 | HIGH | 8.7 | 0.4% | May 8, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Z... |
| CVE-2026-43967 | HIGH | 7.5 | 0.6% | May 8, 2026 | Inefficient Algorithmic Complexity vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service v... |
| CVE-2026-42794 | MEDIUM | 6.1 | 0.3% | May 8, 2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows... |
| CVE-2026-42793 | HIGH | 7.5 | 0.6% | May 8, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated d... |
| CVE-2026-42353 | HIGH | 8.2 | 0.4% | May 8, 2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno... |
| CVE-2026-41886 | HIGH | 7.5 | 0.1% | May 8, 2026 | locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK regi... |
| CVE-2026-41885 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for D... |
| CVE-2026-41883 | HIGH | 8.1 | 0.4% | May 8, 2026 | OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server... |
| CVE-2026-41693 | HIGH | 8.2 | 0.3% | May 8, 2026 | i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem... |
| CVE-2026-41690 | HIGH | 8.6 | 0.3% | May 8, 2026 | 18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno.... |
| CVE-2026-41683 | HIGH | 8.6 | 0.3% | May 8, 2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno... |
| CVE-2026-41591 | MEDIUM | 6.4 | 0.2% | May 8, 2026 | Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/ru... |
| CVE-2026-41070 | CRITICAL | 10 | 0.4% | May 8, 2026 | openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (S... |
| CVE-2026-34354 | HIGH | 7.4 | 0.3% | May 8, 2026 | Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escal... |
| CVE-2026-29975 | HIGH | 7.5 | 0.4% | May 8, 2026 | lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end... |
| CVE-2026-29974 | HIGH | 7.5 | 0.3% | May 8, 2026 | An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a ca... |
| CVE-2026-29972 | HIGH | 8.2 | 0.6% | May 8, 2026 | nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client... |
| CVE-2026-44500 | MEDIUM | 5.3 | 0.4% | May 8, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and p... |
| CVE-2026-44498 | HIGH | 7.5 | 0.3% | May 8, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent ... |
| CVE-2026-44497 | CRITICAL | 9.1 | 0.2% | May 8, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, t... |
| CVE-2026-43475 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Fix scheduling while atomic on PREEM... |
| CVE-2026-43474 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs: init flags_valid before calling vfs_fileattr_ge... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now