2026 CVE Vulnerabilities
64,840 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23927 | MEDIUM | 6.5 | 0.2% | May 6, 2026 | A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead ... |
| CVE-2026-23926 | MEDIUM | 6.8 | 0.3% | May 6, 2026 | An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by... |
| CVE-2026-2306 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation du... |
| CVE-2026-5753 | MEDIUM | 6.5 | 0.3% | May 6, 2026 | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions ... |
| CVE-2026-3208 | MEDIUM | 5.3 | 0.5% | May 6, 2026 | The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a mis... |
| CVE-2026-7573 | HIGH | 7.7 | 0.3% | May 6, 2026 | An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a... |
| CVE-2026-7572 | MEDIUM | 5.5 | 0.1% | May 6, 2026 | An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor befor... |
| CVE-2026-44405 | LOW | 3.4 | 0.1% | May 6, 2026 | In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm. |
| CVE-2026-40934 | MEDIUM | 6.8 | 0.3% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign auth... |
| CVE-2026-40110 | HIGH | 7.3 | 0.3% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation... |
| CVE-2026-40075 | HIGH | 7.5 | 0.6% | May 5, 2026 | OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8... |
| CVE-2026-28780 | CRITICAL | 9.8 | 1.4% | May 5, 2026 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a maliciou... |
| CVE-2026-41950 | MEDIUM | 6.5 | 0.3% | May 5, 2026 | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the fu... |
| CVE-2026-40068 | HIGH | 8.8 | 0.3% | May 5, 2026 | In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir f... |
| CVE-2026-39852 | HIGH | 8.2 | 0.4% | May 5, 2026 | Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3... |
| CVE-2026-39849 | HIGH | 8.8 | 1.0% | May 5, 2026 | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1,... |
| CVE-2026-39402 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_l... |
| CVE-2026-39383 | HIGH | 7.2 | 0.2% | May 5, 2026 | Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access c... |
| CVE-2026-35579 | CRITICAL | 9.8 | 0.5% | May 5, 2026 | CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementati... |
| CVE-2026-35527 | MEDIUM | 5 | 0.3% | May 5, 2026 | Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues ... |
| CVE-2026-7857 | HIGH | 7.3 | 4.2% | May 5, 2026 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file... |
| CVE-2026-7856 | HIGH | 7.3 | 4.6% | May 5, 2026 | A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the comp... |
| CVE-2026-44331 | HIGH | 8.1 | 0.5% | May 5, 2026 | In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap... |
| CVE-2026-40331 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu... |
| CVE-2026-40330 | CRITICAL | 9.3 | 0.4% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 throu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now