2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41905 | HIGH | 7.7 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::san... |
| CVE-2026-41904 | HIGH | 7.6 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with... |
| CVE-2026-41903 | MEDIUM | 5.4 | 0.3% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user hold... |
| CVE-2026-41902 | CRITICAL | 9.1 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-s... |
| CVE-2026-41653 | HIGH | 7 | 0.4% | May 7, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerabilit... |
| CVE-2026-8081 | MEDIUM | 6.3 | 0.2% | May 7, 2026 | A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality... |
| CVE-2026-37709 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958... |
| CVE-2026-7415 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read ... |
| CVE-2026-7414 | CRITICAL | 9.8 | 0.5% | May 7, 2026 | Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials ar... |
| CVE-2026-7413 | CRITICAL | 9.8 | 0.6% | May 7, 2026 | A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authen... |
| CVE-2026-7821 | CRITICAL | 9.1 | 0.5% | May 7, 2026 | Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen... |
| CVE-2026-6973 | HIGH | 7.2 | 34.5% | May 7, 2026 | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic... |
| CVE-2026-5788 | CRITICAL | 9.8 | 0.8% | May 7, 2026 | An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat... |
| CVE-2026-5787 | CRITICAL | 9.1 | 0.7% | May 7, 2026 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut... |
| CVE-2026-5786 | HIGH | 8.8 | 0.7% | May 7, 2026 | An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote... |
| CVE-2026-36388 | MEDIUM | 5.4 | 0.1% | May 7, 2026 | A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/... |
| CVE-2026-36387 | MEDIUM | 6.5 | 0.3% | May 7, 2026 | A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This... |
| CVE-2026-36341 | MEDIUM | 5.4 | 0.2% | May 7, 2026 | Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supp... |
| CVE-2026-44349 | HIGH | 7.1 | 0.3% | May 7, 2026 | Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_finda... |
| CVE-2026-44264 | MEDIUM | 4.3 | 0.3% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other... |
| CVE-2026-44263 | MEDIUM | 4.3 | 0.3% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe... |
| CVE-2026-42011 | HIGH | 7.4 | 0.5% | May 7, 2026 | A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when p... |
| CVE-2026-41689 | MEDIUM | 6 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notifica... |
| CVE-2026-41688 | HIGH | 7.7 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF ... |
| CVE-2026-41687 | MEDIUM | 4.3 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in en... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now