2026 CVE Vulnerabilities
48,075 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47273 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb builds XPath ... |
| CVE-2026-47271 | MEDIUM | 5.1 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, src/mem.c implemented... |
| CVE-2026-44681 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated... |
| CVE-2026-42877 | MEDIUM | 5.4 | 0.2% | May 27, 2026 | FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scriptin... |
| CVE-2026-8716 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, an... |
| CVE-2026-6713 | MEDIUM | 5.3 | 0.3% | May 27, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, an... |
| CVE-2026-5296 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 1... |
| CVE-2026-45046 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine wha... |
| CVE-2026-42879 | MEDIUM | 6.3 | 0.2% | May 27, 2026 | FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricte... |
| CVE-2026-42878 | MEDIUM | 5.3 | 0.2% | May 27, 2026 | FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information discl... |
| CVE-2026-2601 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 1... |
| CVE-2026-1402 | MEDIUM | 6.5 | 0.5% | May 27, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, an... |
| CVE-2026-4392 | MEDIUM | 6.9 | 0.4% | May 27, 2026 | A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown processing of the compo... |
| CVE-2026-4391 | MEDIUM | 6.9 | 0.4% | May 27, 2026 | A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code o... |
| CVE-2026-4390 | MEDIUM | 5.4 | 0.3% | May 27, 2026 | A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the... |
| CVE-2026-48148 | MEDIUM | 5.3 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.35.3, the VectorDB configuration endpoint in Budibase accepts ... |
| CVE-2026-48147 | MEDIUM | 6.5 | 0.1% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages... |
| CVE-2026-48128 | MEDIUM | 5.1 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, the executeQuery automation step in Budibase accepts a qu... |
| CVE-2026-46424 | MEDIUM | 4.2 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/publ... |
| CVE-2026-45719 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation ... |
| CVE-2026-45718 | MEDIUM | 5.4 | 0.1% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:source... |
| CVE-2026-45081 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could a... |
| CVE-2026-42328 | MEDIUM | 6.2 | 0.1% | May 27, 2026 | go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ... |
| CVE-2026-38808 | MEDIUM | 5.3 | 0.3% | May 27, 2026 | SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the Prod... |
| CVE-2026-49054 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Cont... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now