2026 CVE Vulnerabilities
48,280 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41917 | MEDIUM | 6.9 | 0.4% | May 26, 2026 | OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scriptin... |
| CVE-2026-9542 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of ... |
| CVE-2026-9541 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqob... |
| CVE-2026-9540 | MEDIUM | 5.5 | 0.4% | May 26, 2026 | A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component ... |
| CVE-2026-8479 | MEDIUM | 6.9 | 0.2% | May 26, 2026 | IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially craf... |
| CVE-2026-8174 | MEDIUM | 5.7 | 0.4% | May 26, 2026 | Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wo... |
| CVE-2026-7310 | MEDIUM | 4.4 | 0.1% | May 26, 2026 | A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious ... |
| CVE-2026-48136 | MEDIUM | 4.1 | 4.1% | May 26, 2026 | When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access... |
| CVE-2026-48135 | MEDIUM | 5.3 | 2.6% | May 26, 2026 | A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa... |
| CVE-2026-48134 | MEDIUM | 5.6 | 4.4% | May 26, 2026 | When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific... |
| CVE-2026-39642 | MEDIUM | 5.3 | 0.3% | May 26, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code... |
| CVE-2026-27427 | MEDIUM | 6.5 | 0.2% | May 26, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mas... |
| CVE-2026-24638 | MEDIUM | 4.3 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-24590 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Config... |
| CVE-2026-39655 | MEDIUM | 5.3 | 0.2% | May 26, 2026 | Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control... |
| CVE-2026-9534 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cs... |
| CVE-2026-9533 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of th... |
| CVE-2026-9532 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploa... |
| CVE-2026-3314 | MEDIUM | 4.6 | 0.2% | May 26, 2026 | Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hi... |
| CVE-2026-9531 | MEDIUM | 6.3 | 1.8% | May 26, 2026 | A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi... |
| CVE-2026-9527 | MEDIUM | 4.3 | 0.3% | May 26, 2026 | A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing... |
| CVE-2026-9524 | MEDIUM | 6.3 | 0.2% | May 26, 2026 | A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of... |
| CVE-2026-9520 | MEDIUM | 4.3 | 0.3% | May 26, 2026 | A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file pac... |
| CVE-2026-9519 | MEDIUM | 4.3 | 0.3% | May 26, 2026 | A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSidePro... |
| CVE-2026-9518 | MEDIUM | 4.3 | 0.3% | May 26, 2026 | A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now