2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6213 | CRITICAL | 10 | 0.3% | May 8, 2026 | A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check an... |
| CVE-2026-5341 | MEDIUM | 6.4 | 0.3% | May 8, 2026 | The NMR Strava activities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `strava_nmr... |
| CVE-2026-7330 | HIGH | 7.2 | 0.4% | May 8, 2026 | The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ... |
| CVE-2026-5127 | HIGH | 8.8 | 1.0% | May 8, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-44928 | MEDIUM | 5.3 | 0.2% | May 8, 2026 | In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal. |
| CVE-2026-44927 | MEDIUM | 5.3 | 0.2% | May 8, 2026 | In uriparser before 1.0.2, there is pointer difference truncation to int in various places. |
| CVE-2026-43284 | HIGH | 8.8 | 93.2% | May 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb fra... |
| CVE-2026-8149 | MEDIUM | 5.1 | 0.2% | May 8, 2026 | A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on X86_64, AVX, AVX-512f, Linux, Legion of the ... |
| CVE-2026-8069 | HIGH | 7.8 | 0.1% | May 8, 2026 | PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes ... |
| CVE-2026-4935 | HIGH | 8.6 | 0.3% | May 8, 2026 | The OttoKit: All-in-One Automation Platform WordPress plugin before 1.1.23 does not properly sanitize user input before ... |
| CVE-2026-44916 | LOW | 3 | 0.3% | May 8, 2026 | In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered wit... |
| CVE-2026-8148 | HIGH | 7.8 | 0.1% | May 8, 2026 | NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM... |
| CVE-2026-8138 | HIGH | 8.8 | 0.6% | May 8, 2026 | A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /gof... |
| CVE-2026-8137 | HIGH | 8.8 | 0.5% | May 8, 2026 | A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458... |
| CVE-2026-42279 | MEDIUM | 5.8 | 0.3% | May 8, 2026 | solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entr... |
| CVE-2026-42278 | HIGH | 8.8 | 0.4% | May 8, 2026 | UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of Sm... |
| CVE-2026-42277 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint all... |
| CVE-2026-42276 | MEDIUM | 4.3 | 0.3% | May 8, 2026 | Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_se... |
| CVE-2026-8136 | LOW | 2.4 | 0.2% | May 8, 2026 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the fil... |
| CVE-2026-8133 | HIGH | 7.3 | 0.3% | May 8, 2026 | A security vulnerability has been detected in zyx0814 FilePress up to 2.2.0. Affected by this vulnerability is an unknow... |
| CVE-2026-8132 | HIGH | 7.3 | 0.3% | May 8, 2026 | A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /lo... |
| CVE-2026-8131 | HIGH | 7.3 | 0.3% | May 8, 2026 | A security flaw has been discovered in SourceCodester SUP Online Shopping 1.0. This impacts an unknown function of the f... |
| CVE-2026-8130 | HIGH | 7.3 | 0.3% | May 8, 2026 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. This affects an unknown function of the file /... |
| CVE-2026-8129 | HIGH | 7.3 | 0.3% | May 8, 2026 | A vulnerability was determined in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of... |
| CVE-2026-44298 | MEDIUM | 4.9 | 0.3% | May 8, 2026 | Kimai is an open-source time tracking application. From version 2.32.0 to before version 2.56.0, users with the role Sys... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now