2026 CVE Vulnerabilities
48,280 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48905 | MEDIUM | 6.1 | 0.1% | May 26, 2026 | Lack of input filtering leads to an XSS vector in the HTML filter code. |
| CVE-2026-48903 | MEDIUM | 6.1 | 0.1% | May 26, 2026 | Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components. |
| CVE-2026-48900 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. |
| CVE-2026-48693 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. T... |
| CVE-2026-47728 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID wi... |
| CVE-2026-46431 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Orig... |
| CVE-2026-46430 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Li... |
| CVE-2026-45836 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_... |
| CVE-2026-45835 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_... |
| CVE-2026-45834 | MEDIUM | 5.5 | 0.1% | May 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_... |
| CVE-2026-44502 | MEDIUM | 4.3 | 0.3% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypa... |
| CVE-2026-44314 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device ... |
| CVE-2026-35220 | MEDIUM | 4.3 | 0.1% | May 26, 2026 | Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. |
| CVE-2026-30895 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. |
| CVE-2026-30894 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the content history component. |
| CVE-2026-25901 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the multilingual associations component. |
| CVE-2026-25900 | MEDIUM | 6.1 | 0.2% | May 26, 2026 | Lack of output escaping leads to a XSS vector in the feed modules. |
| CVE-2026-48685 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attrib... |
| CVE-2026-48684 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In ... |
| CVE-2026-48683 | MEDIUM | 6.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset p... |
| CVE-2026-46620 | MEDIUM | 6.5 | 0.1% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on c... |
| CVE-2026-43936 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of... |
| CVE-2026-43934 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the applicati... |
| CVE-2026-40564 | MEDIUM | 6.5 | 0.5% | May 26, 2026 | Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Ku... |
| CVE-2026-38587 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw ex... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now