2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41928 | MEDIUM | 6.9 | 0.4% | May 7, 2026 | Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated... |
| CVE-2026-41105 | HIGH | 8.1 | 0.8% | May 7, 2026 | Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges ove... |
| CVE-2026-40214 | MEDIUM | 6.3 | 0.2% | May 7, 2026 | In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. Th... |
| CVE-2026-40213 | HIGH | 7.4 | 0.2% | May 7, 2026 | OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This un... |
| CVE-2026-35435 | CRITICAL | 10 | 1.2% | May 7, 2026 | Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges ... |
| CVE-2026-35428 | CRITICAL | 9.6 | 0.9% | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unaut... |
| CVE-2026-34327 | HIGH | 8.2 | 0.6% | May 7, 2026 | Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attac... |
| CVE-2026-33844 | CRITICAL | 9 | 1.0% | May 7, 2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove... |
| CVE-2026-33823 | MEDIUM | 6.5 | 0.7% | May 7, 2026 | Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. |
| CVE-2026-33111 | HIGH | 7.5 | 1.1% | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all... |
| CVE-2026-33109 | CRITICAL | 9.9 | 0.7% | May 7, 2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code ove... |
| CVE-2026-32207 | MEDIUM | 6.1 | 0.6% | May 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an... |
| CVE-2026-26164 | HIGH | 7.5 | 0.8% | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-26129 | HIGH | 7.5 | 1.1% | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-8098 | HIGH | 7.3 | 0.3% | May 7, 2026 | A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the ... |
| CVE-2026-8097 | MEDIUM | 6.3 | 0.2% | May 7, 2026 | A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the fi... |
| CVE-2026-44365 | — | — | — | May 7, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-34429. Reason: This candidate is a ... |
| CVE-2026-42449 | HIGH | 8.5 | 0.2% | May 7, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In ve... |
| CVE-2026-42047 | HIGH | 8.6 | 0.4% | May 7, 2026 | Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche... |
| CVE-2026-41692 | MEDIUM | 4.7 | 0.1% | May 7, 2026 | i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes.... |
| CVE-2026-41691 | CRITICAL | 9.1 | 0.3% | May 7, 2026 | Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internat... |
| CVE-2026-8142 | MEDIUM | 6.5 | 0.1% | May 7, 2026 | VINCE versions 3.0.38 and earlier do not properly verify the From address authenticity due to encoding confusion and use... |
| CVE-2026-8088 | MEDIUM | 5.5 | 0.2% | May 7, 2026 | A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the ... |
| CVE-2026-8087 | HIGH | 7.8 | 0.2% | May 7, 2026 | A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frm... |
| CVE-2026-43510 | MEDIUM | 5.9 | 0.4% | May 7, 2026 | manage.get.gov is the .gov TLD registrar maintained by CISA. manage.get.gov allows an organization administrator to assi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now