2026 CVE Vulnerabilities
48,008 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47745 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carrie... |
| CVE-2026-47742 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (E... |
| CVE-2026-47741 | MEDIUM | 5.9 | 0.2% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the ... |
| CVE-2026-46344 | MEDIUM | 5.3 | 0.3% | May 29, 2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio... |
| CVE-2026-44652 | MEDIUM | 6.9 | 0.4% | May 29, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-44651 | MEDIUM | 6.9 | 0.3% | May 29, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-44611 | MEDIUM | 5.9 | 0.1% | May 29, 2026 | Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is su... |
| CVE-2026-44518 | MEDIUM | 5.3 | 0.3% | May 29, 2026 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio... |
| CVE-2026-42951 | MEDIUM | 5.9 | 0.2% | May 29, 2026 | An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes accoun... |
| CVE-2026-40425 | MEDIUM | 4.9 | 0.4% | May 29, 2026 | The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file... |
| CVE-2026-45660 | MEDIUM | 5.4 | 0.2% | May 29, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image prox... |
| CVE-2026-45626 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /enviro... |
| CVE-2026-45577 | MEDIUM | 6.9 | 0.2% | May 29, 2026 | Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public... |
| CVE-2026-43917 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware ... |
| CVE-2026-10070 | MEDIUM | 5.1 | 0.2% | May 29, 2026 | A vulnerability was found in macrozheng mall up to 1.0.3. This affects an unknown function of the file /admin/update/ of... |
| CVE-2026-39229 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated atta... |
| CVE-2026-36324 | MEDIUM | 6.1 | 0.2% | May 29, 2026 | SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of use... |
| CVE-2026-35673 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows re... |
| CVE-2026-34507 | MEDIUM | 5.4 | 0.1% | May 29, 2026 | OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated sende... |
| CVE-2026-33384 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same... |
| CVE-2026-32906 | MEDIUM | 4.3 | 0.2% | May 29, 2026 | OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-autho... |
| CVE-2026-10101 | MEDIUM | 6.3 | 0.2% | May 29, 2026 | ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pul... |
| CVE-2026-10099 | MEDIUM | 5.1 | 0.1% | May 29, 2026 | XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_s... |
| CVE-2026-45609 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mc... |
| CVE-2026-41159 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now