2026 CVE Vulnerabilities
48,089 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46424 | MEDIUM | 4.2 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/publ... |
| CVE-2026-45719 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, the V1 Views API (POST /api/views) accepts a calculation ... |
| CVE-2026-45718 | MEDIUM | 5.4 | 0.1% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.38.1, the row action trigger endpoint (POST /api/tables/:source... |
| CVE-2026-45081 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could a... |
| CVE-2026-42328 | MEDIUM | 6.2 | 0.1% | May 27, 2026 | go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ... |
| CVE-2026-38808 | MEDIUM | 5.3 | 0.3% | May 27, 2026 | SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the Prod... |
| CVE-2026-49054 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-45335 | MEDIUM | 5.4 | 0.1% | May 27, 2026 | WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the... |
| CVE-2026-45027 | MEDIUM | 5.9 | 0.1% | May 27, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hash... |
| CVE-2026-44475 | MEDIUM | 6.1 | 0.1% | May 27, 2026 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabil... |
| CVE-2026-44353 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streaml... |
| CVE-2026-44324 | MEDIUM | 6.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscript... |
| CVE-2026-44323 | MEDIUM | 6.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's UDR nudr-dr DELETE /subscript... |
| CVE-2026-44318 | MEDIUM | 5.3 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's BSF PUT /nbsf-management/v1/s... |
| CVE-2026-44317 | MEDIUM | 6.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-policyauthoriz... |
| CVE-2026-42082 | MEDIUM | 5.4 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the... |
| CVE-2026-38931 | MEDIUM | 5.4 | 0.2% | May 27, 2026 | A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp ... |
| CVE-2026-38930 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component... |
| CVE-2026-9674 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows atta... |
| CVE-2026-6957 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to constr... |
| CVE-2026-49102 | MEDIUM | 6.1 | 0.2% | May 27, 2026 | Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes compo... |
| CVE-2026-49059 | MEDIUM | 4.7 | 0.2% | May 27, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. ... |
| CVE-2026-49053 | MEDIUM | 5.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ... |
| CVE-2026-49052 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured ... |
| CVE-2026-49051 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now