2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43289 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: kexec: derive purgatory entry from symbol kexec_lo... |
| CVE-2026-43288 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: move ext4_percpu_param_init() before ext4_mb_... |
| CVE-2026-43287 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm: Account property blob allocations to memcg DR... |
| CVE-2026-43286 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: restore failed global reservations to s... |
| CVE-2026-43285 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not access current->mems_allowed_seq if... |
| CVE-2026-41512 | CRITICAL | 9.9 | 0.6% | May 8, 2026 | ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a r... |
| CVE-2026-41509 | CRITICAL | 9.8 | 0.3% | May 8, 2026 | CROSS implementation contains reference and optimized implementations of the CROSS post-quantum signature algorithm. Pri... |
| CVE-2026-41507 | CRITICAL | 9.8 | 0.4% | May 8, 2026 | math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.p... |
| CVE-2026-41506 | HIGH | 7.4 | 0.3% | May 8, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-gi... |
| CVE-2026-41497 | CRITICAL | 9.8 | 0.5% | May 8, 2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the fix for PraisonAI's MCP command handling does not a... |
| CVE-2026-41496 | HIGH | 8.1 | 0.3% | May 8, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for... |
| CVE-2026-41493 | HIGH | 7.5 | 0.4% | May 8, 2026 | YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when u... |
| CVE-2026-41491 | HIGH | 8.1 | 0.3% | May 8, 2026 | Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. From versions 1.3... |
| CVE-2026-41423 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-41161 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version... |
| CVE-2026-39816 | HIGH | 8.8 | 0.8% | May 8, 2026 | The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Requi... |
| CVE-2026-32803 | LOW | 3.3 | 0.1% | May 8, 2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 ... |
| CVE-2026-8077 | HIGH | 8.6 | 0.2% | May 8, 2026 | Lack of proper authorization implementation in the CashDro 3 web administration panel, version 24.01.00.26. The backend ... |
| CVE-2026-25199 | CRITICAL | 9.1 | 0.5% | May 8, 2026 | Instances deployed via the Proxmox extension allow unauthorized access to instances belonging to other tenants. This... |
| CVE-2026-25077 | HIGH | 8.8 | 0.7% | May 8, 2026 | Account users are allowed by default to register templates to be downloaded directly to the primary storage for deployin... |
| CVE-2026-8153 | CRITICAL | 9.8 | 1.8% | May 8, 2026 | OS command injection in Dashboard Server interface in Universal Robots PolyScope versions prior to 5.25.1 allows unauthe... |
| CVE-2026-8076 | CRITICAL | 9.3 | 0.3% | May 8, 2026 | Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the platform allows the use of nu... |
| CVE-2026-3318 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | Open redirection vulnerability in the latest demo version of the Cradle eCommerce platform. The vulnerability occurs in ... |
| CVE-2026-7650 | MEDIUM | 6.4 | 0.2% | May 8, 2026 | The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id'... |
| CVE-2026-7475 | MEDIUM | 6.4 | 0.2% | May 8, 2026 | The Sky Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `sky-custom-scripts` custom pos... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now