2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43944 | CRITICAL | 9.6 | 0.4% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before ... |
| CVE-2026-43943 | HIGH | 7.8 | 0.2% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code... |
| CVE-2026-43942 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, ... |
| CVE-2026-43941 | CRITICAL | 9.6 | 0.4% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, ... |
| CVE-2026-43940 | HIGH | 8.4 | 0.2% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the r... |
| CVE-2026-42275 | HIGH | 8.7 | 0.3% | May 8, 2026 | zrok is software for sharing web services, files, and network resources. Prior to version 2.0.2, the zrok WebDAV drive b... |
| CVE-2026-42274 | HIGH | 7.8 | 0.4% | May 8, 2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ... |
| CVE-2026-42273 | HIGH | 7.8 | 0.3% | May 8, 2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ... |
| CVE-2026-42272 | HIGH | 7.8 | 0.4% | May 8, 2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall ... |
| CVE-2026-42271 | HIGH | 8.8 | 80.2% | May 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before vers... |
| CVE-2026-42267 | MEDIUM | 5.7 | 0.2% | May 8, 2026 | Kimai is an open-source time tracking application. From version 2.27.0 to before version 2.54.0, any ROLE_USER can creat... |
| CVE-2026-42264 | CRITICAL | 9.1 | 0.7% | May 8, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive con... |
| CVE-2026-42261 | HIGH | 7.1 | 0.2% | May 8, 2026 | PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.... |
| CVE-2026-42208 | CRITICAL | 9.8 | 86.6% | May 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before ver... |
| CVE-2026-42203 | HIGH | 8.8 | 0.4% | May 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before vers... |
| CVE-2026-42150 | MEDIUM | 4.8 | 0.2% | May 8, 2026 | wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc emb... |
| CVE-2026-41900 | CRITICAL | 10 | 0.9% | May 8, 2026 | OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec... |
| CVE-2026-41646 | MEDIUM | 5.5 | 0.1% | May 8, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulner... |
| CVE-2026-41645 | MEDIUM | 5.3 | 0.3% | May 8, 2026 | Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulner... |
| CVE-2026-41501 | CRITICAL | 9.8 | 1.3% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a comm... |
| CVE-2026-41500 | CRITICAL | 9.8 | 1.6% | May 8, 2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a comm... |
| CVE-2026-41498 | LOW | 3.3 | 0.2% | May 8, 2026 | Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit... |
| CVE-2026-8128 | HIGH | 7.3 | 0.3% | May 8, 2026 | A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the ... |
| CVE-2026-8127 | MEDIUM | 6.3 | 0.2% | May 8, 2026 | A vulnerability has been found in eladmin up to 2.7. Impacted is the function checkLevel of the file /rest/UserControlle... |
| CVE-2026-8126 | HIGH | 7.3 | 0.3% | May 8, 2026 | A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now