2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8080 | MEDIUM | 5.4 | 0.1% | May 7, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows... |
| CVE-2026-6508 | CRITICAL | 9.8 | 0.2% | May 7, 2026 | Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Acces... |
| CVE-2026-42285 | HIGH | 7.5 | 0.4% | May 7, 2026 | GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, a... |
| CVE-2026-42010 | CRITICAL | 9.8 | 0.9% | May 7, 2026 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched ... |
| CVE-2026-41644 | HIGH | 7.1 | 0.3% | May 7, 2026 | monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) ... |
| CVE-2026-41643 | HIGH | 7.5 | 0.5% | May 7, 2026 | GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.... |
| CVE-2026-41642 | HIGH | 7.5 | 0.5% | May 7, 2026 | GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a... |
| CVE-2026-3953 | HIGH | 8.8 | 0.3% | May 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software In... |
| CVE-2026-33589 | MEDIUM | 6.5 | 0.2% | May 7, 2026 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to ac... |
| CVE-2026-33588 | HIGH | 8.1 | 0.2% | May 7, 2026 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to cr... |
| CVE-2026-33587 | CRITICAL | 10 | 0.2% | May 7, 2026 | Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subseque... |
| CVE-2026-28201 | HIGH | 7.8 | 0.1% | May 7, 2026 | An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allo... |
| CVE-2026-27415 | MEDIUM | 4.3 | 0.1% | May 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affe... |
| CVE-2026-6805 | HIGH | 7.5 | 0.2% | May 7, 2026 | Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve inf... |
| CVE-2026-44407 | HIGH | 7.5 | 0.3% | May 7, 2026 | A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corrupti... |
| CVE-2026-27421 | MEDIUM | 6.5 | 0.2% | May 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elem... |
| CVE-2026-27416 | MEDIUM | 5.3 | 0.2% | May 7, 2026 | Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2026-27329 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Wishlist allows Exploiting Incor... |
| CVE-2026-25468 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs Happy Addons for Elem... |
| CVE-2026-25436 | MEDIUM | 5.3 | 0.2% | May 7, 2026 | Missing Authorization vulnerability in WProyal Royal Elementor Addons allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-4430 | HIGH | 7.8 | 0.1% | May 7, 2026 | Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched enc... |
| CVE-2026-44406 | HIGH | 7.8 | 0.2% | May 7, 2026 | ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM... |
| CVE-2026-8063 | HIGH | 7.1 | 0.2% | May 7, 2026 | An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When ... |
| CVE-2026-7252 | HIGH | 8.1 | 0.9% | May 7, 2026 | The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress... |
| CVE-2026-6692 | HIGH | 8.8 | 0.8% | May 7, 2026 | The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now