2026 CVE Vulnerabilities
48,280 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48710 | MEDIUM | 6.5 | 1.8% | May 26, 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not valida... |
| CVE-2026-44903 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the ... |
| CVE-2026-44788 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a pa... |
| CVE-2026-44213 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Inst... |
| CVE-2026-42015 | MEDIUM | 5.3 | 0.7% | May 26, 2026 | A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allow... |
| CVE-2026-9583 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This imp... |
| CVE-2026-9582 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Thi... |
| CVE-2026-9581 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/co... |
| CVE-2026-9579 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/logi... |
| CVE-2026-48593 | MEDIUM | 5.9 | 0.3% | May 26, 2026 | Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory e... |
| CVE-2026-48592 | MEDIUM | 5.3 | 0.4% | May 26, 2026 | Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthor... |
| CVE-2026-47672 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any networ... |
| CVE-2026-45413 | MEDIUM | 6.9 | 0.1% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes... |
| CVE-2026-45412 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated u... |
| CVE-2026-44899 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the... |
| CVE-2026-44898 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-c... |
| CVE-2026-44897 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the openin... |
| CVE-2026-44896 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py... |
| CVE-2026-44844 | MEDIUM | 6.3 | 0.4% | May 26, 2026 | eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well... |
| CVE-2026-44836 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3... |
| CVE-2026-44708 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline m... |
| CVE-2026-44443 | MEDIUM | 4.8 | 0.1% | May 26, 2026 | Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level varia... |
| CVE-2026-42337 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vul... |
| CVE-2026-42336 | MEDIUM | 5.1 | 0.2% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forge... |
| CVE-2026-42335 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-s... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now