2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7742 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /Online... |
| CVE-2026-7741 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClass... |
| CVE-2026-7740 | LOW | 3.3 | 0.1% | May 4, 2026 | A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit:... |
| CVE-2026-7739 | LOW | 3.3 | 0.1% | May 4, 2026 | A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::se... |
| CVE-2026-7738 | MEDIUM | 6.3 | 0.3% | May 4, 2026 | A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_do... |
| CVE-2026-7737 | HIGH | 7.5 | 0.6% | May 4, 2026 | A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.P... |
| CVE-2026-7736 | HIGH | 7.5 | 0.5% | May 4, 2026 | A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry o... |
| CVE-2026-5335 | MEDIUM | 5.3 | 0.3% | May 4, 2026 | The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, mak... |
| CVE-2026-43864 | LOW | 2.5 | 0.1% | May 4, 2026 | mutt before 2.3.2 has a show_sig_summary NULL pointer dereference. |
| CVE-2026-43863 | LOW | 3.7 | 0.2% | May 4, 2026 | mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c. |
| CVE-2026-43862 | LOW | 3.7 | 0.2% | May 4, 2026 | In mutt before 2.3.2, the imap_auth_gss security level is mishandled. |
| CVE-2026-43861 | LOW | 3.7 | 0.2% | May 4, 2026 | mutt before 2.3.2 does not check for '\0' in url_pct_decode. |
| CVE-2026-43860 | LOW | 3.7 | 0.2% | May 4, 2026 | mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest. |
| CVE-2026-43859 | LOW | 3.7 | 0.2% | May 4, 2026 | mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest. |
| CVE-2026-29200 | CRITICAL | 9.9 | 0.3% | May 4, 2026 | A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2... |
| CVE-2026-29199 | HIGH | 8.1 | 0.2% | May 4, 2026 | phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_ser... |
| CVE-2026-20451 | MEDIUM | 6.7 | 0.2% | May 4, 2026 | In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege... |
| CVE-2026-20450 | MEDIUM | 6.5 | 0.3% | May 4, 2026 | In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,... |
| CVE-2026-20449 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, i... |
| CVE-2026-20448 | MEDIUM | 6.7 | 0.1% | May 4, 2026 | In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es... |
| CVE-2026-20447 | MEDIUM | 6.7 | 0.1% | May 4, 2026 | In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escala... |
| CVE-2026-7735 | HIGH | 7.3 | 0.4% | May 4, 2026 | A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the f... |
| CVE-2026-7734 | HIGH | 7.5 | 0.5% | May 4, 2026 | A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromByt... |
| CVE-2026-7733 | HIGH | 7.3 | 0.3% | May 4, 2026 | A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/... |
| CVE-2026-7732 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now