2026 CVE Vulnerabilities
48,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48589 | MEDIUM | 5.4 | 0.4% | May 25, 2026 | Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In ... |
| CVE-2026-44598 | MEDIUM | 5.4 | 0.4% | May 25, 2026 | With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vu... |
| CVE-2026-43828 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue... |
| CVE-2026-43827 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 ... |
| CVE-2026-24597 | MEDIUM | 4.3 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This ... |
| CVE-2026-24574 | MEDIUM | 6.5 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Fo... |
| CVE-2026-24545 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2026-9498 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass ... |
| CVE-2026-9497 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject ... |
| CVE-2026-9486 | MEDIUM | 4.3 | 0.2% | May 25, 2026 | A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part... |
| CVE-2026-9484 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is... |
| CVE-2026-48849 | MEDIUM | 4.4 | 0.2% | May 25, 2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored valu... |
| CVE-2026-48846 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a... |
| CVE-2026-48845 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for U... |
| CVE-2026-24546 | MEDIUM | 5.3 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2026-9483 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the... |
| CVE-2026-9473 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileConten... |
| CVE-2026-9472 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the funct... |
| CVE-2026-27768 | MEDIUM | 6.6 | 0.3% | May 25, 2026 | SQL Injection affecting the Access Manager role. |
| CVE-2026-9468 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The a... |
| CVE-2026-9467 | MEDIUM | 4.3 | 0.4% | May 25, 2026 | A vulnerability was identified in debugmcp mcp-debugger up to 0.20.0. Impacted is the function handleGetSourceContext of... |
| CVE-2026-9466 | MEDIUM | 5.5 | 0.4% | May 25, 2026 | A vulnerability was determined in Tiandy Easy7 Integrated Management Platform 7.17.0. This issue affects some unknown pr... |
| CVE-2026-42797 | MEDIUM | 4.9 | 0.4% | May 25, 2026 | Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope. An administrator with adequate ... |
| CVE-2026-9464 | MEDIUM | 4.7 | 0.4% | May 25, 2026 | A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the fil... |
| CVE-2026-9078 | MEDIUM | 5.4 | 0.2% | May 25, 2026 | Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now