2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44515 | LOW | 2.3 | 0.2% | May 14, 2026 | Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feed... |
| CVE-2026-44348 | LOW | 2.5 | 0.1% | May 14, 2026 | PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha... |
| CVE-2026-7471 | LOW | 3.5 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18... |
| CVE-2026-2900 | LOW | 2.7 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 1... |
| CVE-2026-33585 | LOW | 3.8 | 0.1% | May 13, 2026 | Improper management of the idle timeout parameter in the Keycloak interface of the Arqit SKA-Platform enables an attacke... |
| CVE-2026-0238 | LOW | 3.2 | 0.1% | May 13, 2026 | A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into c... |
| CVE-2026-44582 | LOW | 3.7 | 0.2% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React S... |
| CVE-2026-44459 | LOW | 3.8 | 0.2% | May 13, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validat... |
| CVE-2026-42158 | LOW | 2.3 | 0.2% | May 12, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-44242 | LOW | 3.7 | 0.2% | May 12, 2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat... |
| CVE-2026-44220 | LOW | 3.2 | 0.2% | May 12, 2026 | ciguard is a static security auditor for CI/CD pipelines. From 0.8.0 to 0.8.1 , the discover_pipeline_files() function i... |
| CVE-2026-44219 | LOW | 3.7 | 0.3% | May 12, 2026 | ciguard is a static security auditor for CI/CD pipelines. From 0.6.0 to 0.8.1, both SCA HTTP clients (src/ciguard/analyz... |
| CVE-2026-44218 | LOW | 3 | 0.1% | May 12, 2026 | ciguard is a static security auditor for CI/CD pipelines. From 0.1.0 to 0.8.1, the published ghcr.io/jo-jo98/ciguard con... |
| CVE-2026-34685 | LOW | 3.4 | 0.4% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an ... |
| CVE-2026-41611 | LOW | 3.3 | 0.4% | May 12, 2026 | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthoriz... |
| CVE-2026-20793 | LOW | 3.3 | 0.1% | May 12, 2026 | Unchecked return value for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User Applic... |
| CVE-2026-43514 | LOW | 3.7 | 0.4% | May 12, 2026 | Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomca... |
| CVE-2026-32684 | LOW | 2.9 | 0.1% | May 12, 2026 | The application does not impose strict enough restrictions on directory access permissions, posing a risk that other mal... |
| CVE-2026-40131 | LOW | 3.4 | 0.2% | May 12, 2026 | SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user ... |
| CVE-2026-45362 | LOW | 3.2 | 0.1% | May 12, 2026 | Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file. |
| CVE-2026-42188 | LOW | 2.4 | 0.2% | May 11, 2026 | Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request... |
| CVE-2026-28957 | LOW | 3.3 | 0.1% | May 11, 2026 | An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPa... |
| CVE-2026-28910 | LOW | 3.3 | 0.1% | May 11, 2026 | This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app ma... |
| CVE-2026-42874 | LOW | 3.7 | 0.2% | May 11, 2026 | Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its ... |
| CVE-2026-43969 | LOW | 3.2 | 0.1% | May 11, 2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now