2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7875 | CRITICAL | 9.3 | 0.1% | May 6, 2026 | NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment hand... |
| CVE-2026-42503 | HIGH | 8.8 | 0.2% | May 6, 2026 | gopls by default communicates via pipe. However, -port and -listen flags are supported as means of debugging. If -listen... |
| CVE-2026-29080 | HIGH | 8.8 | 0.3% | May 6, 2026 | A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbit... |
| CVE-2026-23870 | HIGH | 7.5 | 1.5% | May 6, 2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpo... |
| CVE-2026-21661 | HIGH | 8.4 | 0.1% | May 6, 2026 | An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Co... |
| CVE-2026-20219 | MEDIUM | 5.4 | 0.2% | May 6, 2026 | A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social... |
| CVE-2026-20195 | MEDIUM | 5.3 | 0.3% | May 6, 2026 | A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to e... |
| CVE-2026-20193 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with ... |
| CVE-2026-20189 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, ... |
| CVE-2026-20188 | NONE | 0 | 0.3% | May 6, 2026 | Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork ... |
| CVE-2026-20185 | HIGH | 7.7 | 0.4% | May 6, 2026 | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG... |
| CVE-2026-20172 | MEDIUM | 4.3 | 0.1% | May 6, 2026 | A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote ... |
| CVE-2026-20169 | MEDIUM | 6.4 | 0.2% | May 6, 2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, ... |
| CVE-2026-20168 | MEDIUM | 6.5 | 0.3% | May 6, 2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, ... |
| CVE-2026-20167 | HIGH | 7.7 | 0.3% | May 6, 2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, ... |
| CVE-2026-20035 | HIGH | 7.2 | 0.4% | May 6, 2026 | A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to con... |
| CVE-2026-20034 | HIGH | 8.8 | 0.7% | May 6, 2026 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att... |
| CVE-2026-6863 | MEDIUM | 6.8 | 0.2% | May 6, 2026 | Velociraptor versions prior to 0.76.4 contain a cross organization authorization bypass in the HTTP API. A user with onl... |
| CVE-2026-6788 | HIGH | 7.8 | 0.1% | May 6, 2026 | Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files. |
| CVE-2026-6787 | HIGH | 7.8 | 0.1% | May 6, 2026 | Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Pr... |
| CVE-2026-6691 | HIGH | 8.6 | 0.1% | May 6, 2026 | The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling ... |
| CVE-2026-41288 | HIGH | 7.8 | 0.1% | May 6, 2026 | Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allo... |
| CVE-2026-41286 | MEDIUM | 6.5 | 0.2% | May 6, 2026 | Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. ... |
| CVE-2026-8028 | LOW | 3.7 | 0.4% | May 6, 2026 | A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/se... |
| CVE-2026-8027 | MEDIUM | 5.3 | 0.3% | May 6, 2026 | A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functiona... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now