2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9306 | LOW | 3.7 | 0.3% | May 23, 2026 | A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourne... |
| CVE-2026-39824 | LOW | 3.3 | 0.1% | May 22, 2026 | NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum siz... |
| CVE-2026-39967 | LOW | 3.1 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter r... |
| CVE-2026-9249 | LOW | 3.1 | 0.1% | May 22, 2026 | Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the pr... |
| CVE-2026-9248 | LOW | 2.6 | 0.1% | May 22, 2026 | Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce... |
| CVE-2026-9247 | LOW | 2.4 | 0.2% | May 22, 2026 | Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissi... |
| CVE-2026-8477 | LOW | 2.7 | 0.2% | May 22, 2026 | Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al... |
| CVE-2026-25608 | LOW | 2.3 | 0.2% | May 22, 2026 | STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middl... |
| CVE-2026-7837 | LOW | 3.7 | 0.2% | May 21, 2026 | A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-pr... |
| CVE-2026-44075 | LOW | 3.7 | 0.3% | May 21, 2026 | A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch... |
| CVE-2026-44074 | LOW | 3.7 | 0.3% | May 21, 2026 | Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when mu... |
| CVE-2026-44071 | LOW | 3.7 | 0.3% | May 21, 2026 | Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at ru... |
| CVE-2026-44057 | LOW | 3.1 | 0.2% | May 21, 2026 | A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code pat... |
| CVE-2026-7836 | LOW | 3.1 | 0.3% | May 21, 2026 | An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handl... |
| CVE-2026-7835 | LOW | 3.1 | 0.3% | May 21, 2026 | A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a mino... |
| CVE-2026-44072 | LOW | 3 | 0.1% | May 21, 2026 | Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which ... |
| CVE-2026-44070 | LOW | 3.1 | 0.3% | May 21, 2026 | An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenti... |
| CVE-2026-44069 | LOW | 3.9 | 0.1% | May 21, 2026 | An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain l... |
| CVE-2026-47068 | LOW | 2.3 | 0.4% | May 20, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session P... |
| CVE-2026-45232 | LOW | 3.7 | 0.3% | May 20, 2026 | Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connect... |
| CVE-2026-8492 | LOW | 2.7 | 0.2% | May 19, 2026 | Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource L... |
| CVE-2026-8491 | LOW | 3.7 | 0.2% | May 19, 2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Brows... |
| CVE-2026-5511 | LOW | 2.7 | 0.2% | May 19, 2026 | In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i... |
| CVE-2026-7860 | LOW | 1.6 | 0.1% | May 19, 2026 | A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes ... |
| CVE-2026-33565 | LOW | 3.3 | 0.1% | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now