2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10078 | LOW | 2.7 | 0.2% | May 29, 2026 | A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec... |
| CVE-2026-9991 | LOW | 3.1 | 0.1% | May 28, 2026 | Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who ... |
| CVE-2026-9959 | LOW | 3.1 | 0.1% | May 28, 2026 | Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data v... |
| CVE-2026-9950 | LOW | 3.1 | 0.2% | May 28, 2026 | Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attac... |
| CVE-2026-9944 | LOW | 3.1 | 0.2% | May 28, 2026 | Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the re... |
| CVE-2026-9920 | LOW | 3.1 | 0.2% | May 28, 2026 | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromis... |
| CVE-2026-6816 | LOW | 3.8 | 0.3% | May 28, 2026 | An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or ... |
| CVE-2026-10011 | LOW | 3.1 | 0.2% | May 28, 2026 | Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromi... |
| CVE-2026-45403 | LOW | 2.5 | 0.2% | May 28, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-47337 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET... |
| CVE-2026-47336 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 so... |
| CVE-2026-47330 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitializ... |
| CVE-2026-47329 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor n... |
| CVE-2026-47327 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmo... |
| CVE-2026-45076 | LOW | 2.7 | 0.4% | May 28, 2026 | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers ... |
| CVE-2026-48524 | LOW | 3.7 | 0.2% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP r... |
| CVE-2026-48156 | LOW | 3.3 | 0.1% | May 28, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr... |
| CVE-2026-9828 | LOW | 2.9 | 0.4% | May 28, 2026 | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-... |
| CVE-2026-49009 | LOW | 3.1 | 0.5% | May 27, 2026 | Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. |
| CVE-2026-33552 | LOW | 3.7 | 0.3% | May 27, 2026 | Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control. |
| CVE-2026-44474 | LOW | 3.7 | 0.1% | May 27, 2026 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concur... |
| CVE-2026-9712 | LOW | 3.8 | 0.2% | May 27, 2026 | When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, ra... |
| CVE-2026-46057 | LOW | 3.3 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: landlock: Fix LOG_SUBDOMAINS_OFF inheritance across... |
| CVE-2026-42791 | LOW | 3.7 | 0.3% | May 27, 2026 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses... |
| CVE-2026-9608 | LOW | 2.4 | 0.2% | May 27, 2026 | A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /T... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now