2026 CVE Vulnerabilities
64,840 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40329 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exist... |
| CVE-2026-40280 | HIGH | 7.5 | 0.5% | May 5, 2026 | Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists fo... |
| CVE-2026-38947 | MEDIUM | 6.1 | 0.2% | May 5, 2026 | FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin. |
| CVE-2026-35453 | MEDIUM | 5.4 | 0.2% | May 5, 2026 | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1... |
| CVE-2026-35397 | HIGH | 8.8 | 0.6% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerabili... |
| CVE-2026-34596 | HIGH | 7 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of... |
| CVE-2026-34527 | MEDIUM | 5.3 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniSe... |
| CVE-2026-34464 | HIGH | 8.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipe... |
| CVE-2026-34462 | HIGH | 7.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P... |
| CVE-2026-34461 | HIGH | 7.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI... |
| CVE-2026-34459 | HIGH | 8.8 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieS... |
| CVE-2026-34458 | HIGH | 8.8 | 0.3% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI in... |
| CVE-2026-34084 | CRITICAL | 9.8 | 0.7% | May 5, 2026 | PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1... |
| CVE-2026-33975 | HIGH | 8.3 | 0.2% | May 5, 2026 | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-... |
| CVE-2026-33489 | HIGH | 7.5 | 0.4% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL s... |
| CVE-2026-33420 | MEDIUM | 5.3 | 0.2% | May 5, 2026 | Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_det... |
| CVE-2026-33324 | HIGH | 8.8 | 0.6% | May 5, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the T... |
| CVE-2026-33190 | HIGH | 7.5 | 0.4% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D... |
| CVE-2026-32936 | HIGH | 7.5 | 0.7% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts over... |
| CVE-2026-32934 | HIGH | 7.5 | 0.5% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven i... |
| CVE-2026-32699 | MEDIUM | 5.3 | 0.3% | May 5, 2026 | FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fai... |
| CVE-2026-32603 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial... |
| CVE-2026-31893 | MEDIUM | 5.5 | 0.2% | May 5, 2026 | Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any ... |
| CVE-2026-7855 | HIGH | 7.2 | 1.1% | May 5, 2026 | A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /... |
| CVE-2026-7854 | CRITICAL | 9.8 | 5.9% | May 5, 2026 | A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now