2026 CVE Vulnerabilities
48,018 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43979 | MEDIUM | 5 | 0.3% | May 28, 2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdo... |
| CVE-2026-46561 | MEDIUM | 5 | 0.2% | May 28, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based p... |
| CVE-2026-45307 | MEDIUM | 6.1 | 0.2% | May 28, 2026 | Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the... |
| CVE-2026-45306 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509... |
| CVE-2026-45297 | MEDIUM | 5.3 | 0.2% | May 28, 2026 | OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assi... |
| CVE-2026-45021 | MEDIUM | 5.1 | 0.2% | May 28, 2026 | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2... |
| CVE-2026-44796 | MEDIUM | 6.5 | 0.3% | May 28, 2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bul... |
| CVE-2026-44794 | MEDIUM | 5.4 | 0.2% | May 28, 2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-o... |
| CVE-2026-9091 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass c... |
| CVE-2026-47676 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() stri... |
| CVE-2026-47675 | MEDIUM | 5.3 | 0.2% | May 28, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() ... |
| CVE-2026-47674 | MEDIUM | 5.3 | 0.2% | May 28, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restricti... |
| CVE-2026-47673 | MEDIUM | 6.5 | 0.2% | May 28, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk ... |
| CVE-2026-45292 | MEDIUM | 5.3 | 1.1% | May 28, 2026 | opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing tel... |
| CVE-2026-45078 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synaps... |
| CVE-2026-41185 | MEDIUM | 6.5 | 0.3% | May 28, 2026 | When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to at... |
| CVE-2026-41184 | MEDIUM | 6.5 | 0.5% | May 28, 2026 | In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration... |
| CVE-2026-41160 | MEDIUM | 4.3 | 0.3% | May 28, 2026 | EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Ac... |
| CVE-2026-41141 | MEDIUM | 6.5 | 0.3% | May 28, 2026 | EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:... |
| CVE-2026-48735 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr... |
| CVE-2026-48525 | MEDIUM | 5.3 | 0.3% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u... |
| CVE-2026-48523 | MEDIUM | 5.4 | 0.1% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list ... |
| CVE-2026-48522 | MEDIUM | 4.2 | 0.2% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to url... |
| CVE-2026-48155 | MEDIUM | 5.5 | 0.1% | May 28, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr... |
| CVE-2026-47762 | MEDIUM | 5.4 | 0.2% | May 28, 2026 | TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now