2026 CVE Vulnerabilities
48,012 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41159 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ... |
| CVE-2026-41150 | MEDIUM | 5.3 | 0.4% | May 29, 2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 ... |
| CVE-2026-49325 | MEDIUM | 4.6 | 0.2% | May 29, 2026 | Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 ... |
| CVE-2026-49316 | MEDIUM | 4.6 | 0.2% | May 29, 2026 | Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allow... |
| CVE-2026-47696 | MEDIUM | 4.3 | 0.1% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits t... |
| CVE-2026-47694 | MEDIUM | 5.4 | 0.2% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input a... |
| CVE-2026-46337 | MEDIUM | 5.3 | 0.5% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary... |
| CVE-2026-45731 | MEDIUM | 4.9 | 0.5% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relat... |
| CVE-2026-45620 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or... |
| CVE-2026-45619 | MEDIUM | 6.5 | 0.1% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and o... |
| CVE-2026-45610 | MEDIUM | 6.5 | 0.1% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o... |
| CVE-2026-45582 | MEDIUM | 6.5 | 0.3% | May 29, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-45580 | MEDIUM | 5.4 | 0.1% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability.... |
| CVE-2026-40510 | MEDIUM | 6.8 | 0.2% | May 29, 2026 | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history... |
| CVE-2026-10075 | MEDIUM | 6.9 | 0.4% | May 29, 2026 | DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read ... |
| CVE-2026-10074 | MEDIUM | 6.9 | 0.3% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo... |
| CVE-2026-49324 | MEDIUM | 4.6 | 0.2% | May 29, 2026 | Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025... |
| CVE-2026-49323 | MEDIUM | 4.3 | 0.1% | May 29, 2026 | Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcyc... |
| CVE-2026-45551 | MEDIUM | 5.1 | 0.2% | May 29, 2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.1... |
| CVE-2026-9811 | MEDIUM | 5.4 | 0.1% | May 29, 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering s... |
| CVE-2026-9557 | MEDIUM | 6.4 | 0.1% | May 29, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of... |
| CVE-2026-42965 | MEDIUM | 6.5 | 0.2% | May 29, 2026 | A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creat... |
| CVE-2026-9189 | MEDIUM | 5.3 | 0.2% | May 29, 2026 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verifi... |
| CVE-2026-49198 | MEDIUM | 4.9 | 0.2% | May 29, 2026 | Improper access control in the MQTT broker allows wildcard topic subscriptions, exposing all MQTT traffic to unauthorize... |
| CVE-2026-10058 | MEDIUM | 4.8 | 0.2% | May 29, 2026 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now