2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7776 | HIGH | 7.5 | 0.2% | May 4, 2026 | Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition ... |
| CVE-2026-7779 | MEDIUM | 4.3 | 0.4% | May 4, 2026 | A security flaw has been discovered in Open5GS up to 2.7.7. Affected is the function udm_nudr_dr_handle_subscription_aut... |
| CVE-2026-42238 | CRITICAL | 9.8 | 0.8% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore end... |
| CVE-2026-42223 | MEDIUM | 6.5 | 0.3% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/sett... |
| CVE-2026-42222 | CRITICAL | 9.8 | 0.3% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exist... |
| CVE-2026-42221 | CRITICAL | 9.8 | 0.3% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticate... |
| CVE-2026-42220 | MEDIUM | 6.5 | 0.3% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /a... |
| CVE-2026-7768 | HIGH | 7.5 | 0.3% | May 4, 2026 | @fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit ... |
| CVE-2026-6321 | HIGH | 7.5 | 0.6% | May 4, 2026 | fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize()... |
| CVE-2026-41927 | HIGH | 8.3 | 0.4% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firew... |
| CVE-2026-41926 | CRITICAL | 9.3 | 1.2% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cg... |
| CVE-2026-41925 | CRITICAL | 9.3 | 3.4% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi bin... |
| CVE-2026-41924 | CRITICAL | 9.3 | 2.7% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest... |
| CVE-2026-41923 | CRITICAL | 9.3 | 2.6% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cg... |
| CVE-2026-41922 | CRITICAL | 9.3 | 5.0% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cg... |
| CVE-2026-34882 | — | — | — | May 4, 2026 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-6074. Reason: This record is a reservation duplicate o... |
| CVE-2026-43964 | HIGH | 7.5 | 0.5% | May 4, 2026 | Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash v... |
| CVE-2026-42237 | HIGH | 8.8 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f... |
| CVE-2026-42236 | HIGH | 7.5 | 0.5% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client... |
| CVE-2026-42235 | CRITICAL | 9.6 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated a... |
| CVE-2026-42234 | HIGH | 8.8 | 0.4% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use... |
| CVE-2026-42233 | CRITICAL | 9.8 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle... |
| CVE-2026-42232 | HIGH | 8.8 | 0.5% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use... |
| CVE-2026-42231 | HIGH | 8.8 | 0.9% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js... |
| CVE-2026-42230 | MEDIUM | 6.1 | 0.2% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/regis... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now