2026 CVE Vulnerabilities
43,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6737 | LOW | 2 | 0.1% | May 8, 2026 | An Exposed IOCTL with Insufficient Access Control vulnerability in AsusPTPFilter allows a local user to bypass driver se... |
| CVE-2026-41663 | LOW | 3.5 | 0.1% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio... |
| CVE-2026-41659 | LOW | 2.7 | 0.3% | May 7, 2026 | Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (m... |
| CVE-2026-8022 | LOW | 3.1 | 0.2% | May 6, 2026 | Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a ... |
| CVE-2026-8017 | LOW | 3.1 | 0.1% | May 6, 2026 | Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cros... |
| CVE-2026-7968 | LOW | 3.1 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who... |
| CVE-2026-7966 | LOW | 3.1 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote att... |
| CVE-2026-7965 | LOW | 3.1 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker... |
| CVE-2026-7959 | LOW | 3.1 | 0.2% | May 6, 2026 | Inappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had com... |
| CVE-2026-7954 | LOW | 3.1 | 0.2% | May 6, 2026 | Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the rendere... |
| CVE-2026-7949 | LOW | 3.1 | 0.2% | May 6, 2026 | Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the ren... |
| CVE-2026-7945 | LOW | 3.1 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who... |
| CVE-2026-7944 | LOW | 3.1 | 0.2% | May 6, 2026 | Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.96 allowed a remote ... |
| CVE-2026-7937 | LOW | 3.1 | 0.1% | May 6, 2026 | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a ... |
| CVE-2026-7909 | LOW | 3.1 | 0.2% | May 6, 2026 | Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had ... |
| CVE-2026-8028 | LOW | 3.7 | 0.4% | May 6, 2026 | A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/se... |
| CVE-2026-44405 | LOW | 3.4 | 0.1% | May 6, 2026 | In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm. |
| CVE-2026-7847 | LOW | 2.6 | 0.2% | May 5, 2026 | A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_... |
| CVE-2026-7846 | LOW | 2.6 | 0.2% | May 5, 2026 | A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the... |
| CVE-2026-7845 | LOW | 2.6 | 0.1% | May 5, 2026 | A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.toby... |
| CVE-2026-43529 | LOW | 2.5 | 0.1% | May 5, 2026 | OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed func... |
| CVE-2026-6499 | LOW | 2.4 | 0.1% | May 4, 2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Bina... |
| CVE-2026-7740 | LOW | 3.3 | 0.1% | May 4, 2026 | A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit:... |
| CVE-2026-7739 | LOW | 3.3 | 0.1% | May 4, 2026 | A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::se... |
| CVE-2026-43864 | LOW | 2.5 | 0.1% | May 4, 2026 | mutt before 2.3.2 has a show_sig_summary NULL pointer dereference. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now