2026 CVE Vulnerabilities
48,008 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10116 | MEDIUM | 4.3 | 0.4% | May 30, 2026 | A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in ... |
| CVE-2026-10115 | MEDIUM | 4.3 | 0.3% | May 30, 2026 | A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.... |
| CVE-2026-10114 | MEDIUM | 4.3 | 0.3% | May 30, 2026 | A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the lib... |
| CVE-2026-10113 | MEDIUM | 4.3 | 0.3% | May 30, 2026 | A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the libr... |
| CVE-2026-48840 | MEDIUM | 5.3 | 0.3% | May 30, 2026 | Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of unini... |
| CVE-2026-9831 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-c... |
| CVE-2026-48811 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a ... |
| CVE-2026-48810 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating... |
| CVE-2026-45294 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset ... |
| CVE-2026-44640 | MEDIUM | 4.5 | 0.1% | May 29, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_... |
| CVE-2026-44287 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/... |
| CVE-2026-42500 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid ... |
| CVE-2026-34127 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG... |
| CVE-2026-49386 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles ... |
| CVE-2026-49385 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service account... |
| CVE-2026-49384 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible |
| CVE-2026-49381 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
| CVE-2026-49380 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
| CVE-2026-49379 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
| CVE-2026-49378 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
| CVE-2026-49377 | MEDIUM | 4.3 | 0.7% | May 29, 2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
| CVE-2026-49376 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
| CVE-2026-49375 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page |
| CVE-2026-49369 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages |
| CVE-2026-49368 | MEDIUM | 5.4 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now