2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9567 | LOW | 3.3 | 0.1% | May 26, 2026 | A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia... |
| CVE-2026-42448 | LOW | 3.5 | 0.2% | May 26, 2026 | Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.2... |
| CVE-2026-9564 | LOW | 2.4 | 0.2% | May 26, 2026 | A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted elem... |
| CVE-2026-47716 | LOW | 3.1 | 0.1% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes acces... |
| CVE-2026-47715 | LOW | 3.1 | 0.2% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier... |
| CVE-2026-44410 | LOW | 3.8 | 0.1% | May 26, 2026 | This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended... |
| CVE-2026-9530 | LOW | 3.3 | 0.1% | May 26, 2026 | A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_sec... |
| CVE-2026-9529 | LOW | 3.3 | 0.1% | May 26, 2026 | A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER ... |
| CVE-2026-9504 | LOW | 3.3 | 0.2% | May 25, 2026 | A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/... |
| CVE-2026-9503 | LOW | 3.3 | 0.1% | May 25, 2026 | A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file sr... |
| CVE-2026-9501 | LOW | 3.3 | 0.1% | May 25, 2026 | A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section... |
| CVE-2026-48852 | LOW | 3.7 | 0.3% | May 25, 2026 | PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification. |
| CVE-2026-48851 | LOW | 3.1 | 0.2% | May 25, 2026 | PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not c... |
| CVE-2026-9485 | LOW | 3.5 | 0.2% | May 25, 2026 | A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some un... |
| CVE-2026-48847 | LOW | 3.7 | 0.4% | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redi... |
| CVE-2026-9471 | LOW | 3.5 | 0.2% | May 25, 2026 | A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This ... |
| CVE-2026-9414 | LOW | 3.5 | 0.2% | May 25, 2026 | A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an ... |
| CVE-2026-48832 | LOW | 3.5 | 0.2% | May 24, 2026 | action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability. |
| CVE-2026-9398 | LOW | 3.1 | 0.3% | May 24, 2026 | A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown par... |
| CVE-2026-9396 | LOW | 3.7 | 0.3% | May 24, 2026 | A security flaw has been discovered in Besen BS20 EV Charging Station up to 20260426. Affected by this vulnerability is ... |
| CVE-2026-9395 | LOW | 3.5 | 0.2% | May 24, 2026 | A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the ... |
| CVE-2026-9394 | LOW | 3.1 | 0.2% | May 24, 2026 | A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the... |
| CVE-2026-9377 | LOW | 2.4 | 0.2% | May 24, 2026 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of... |
| CVE-2026-9370 | LOW | 3.7 | 0.2% | May 24, 2026 | A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is ... |
| CVE-2026-9357 | LOW | 3.5 | 0.3% | May 24, 2026 | A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now