2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4348 | HIGH | 7.5 | 0.4% | May 7, 2026 | The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_... |
| CVE-2026-41641 | HIGH | 7.2 | 1.8% | May 7, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-41586 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applica... |
| CVE-2026-41413 | HIGH | 7.7 | 0.3% | May 7, 2026 | Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a Requ... |
| CVE-2026-41143 | HIGH | 8.8 | 0.3% | May 7, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerabi... |
| CVE-2026-41139 | HIGH | 8.8 | 0.6% | May 7, 2026 | Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary... |
| CVE-2026-6214 | MEDIUM | 6.5 | 0.4% | May 7, 2026 | The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0.... |
| CVE-2026-44603 | CRITICAL | 9.1 | 0.3% | May 7, 2026 | Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007. |
| CVE-2026-44602 | HIGH | 7.5 | 0.3% | May 7, 2026 | Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. |
| CVE-2026-44601 | HIGH | 7.5 | 0.3% | May 7, 2026 | Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close o... |
| CVE-2026-42217 | CRITICAL | 9.8 | 0.4% | May 7, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-42216 | CRITICAL | 9.1 | 0.4% | May 7, 2026 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2026-42194 | MEDIUM | 6.8 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_m... |
| CVE-2026-41891 | MEDIUM | 5.3 | 0.3% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41890 | MEDIUM | 6.9 | 0.3% | May 7, 2026 | CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati... |
| CVE-2026-41675 | HIGH | 7.5 | 0.4% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41674 | HIGH | 7.5 | 0.5% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41673 | HIGH | 7.5 | 0.6% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41672 | HIGH | 7.5 | 0.4% | May 7, 2026 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom... |
| CVE-2026-41671 | MEDIUM | 6.8 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modu... |
| CVE-2026-41670 | HIGH | 8.2 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO... |
| CVE-2026-41669 | HIGH | 8.2 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implement... |
| CVE-2026-41663 | LOW | 3.5 | 0.1% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio... |
| CVE-2026-41662 | MEDIUM | 5.2 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify wheth... |
| CVE-2026-41661 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now