2026 CVE Vulnerabilities
48,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47076 | MEDIUM | 6.5 | 0.2% | May 25, 2026 | Interpretation Conflict vulnerability in benoitc hackney allows Server Side Request Forgery. hackney_url:normalize/2 URL... |
| CVE-2026-47070 | MEDIUM | 6.1 | 0.3% | May 25, 2026 | Sensitive Data Exposure vulnerability in benoitc hackney allows Retrieve Embedded Sensitive Data. The HTTP/3 redirect ha... |
| CVE-2026-47069 | MEDIUM | 5.3 | 0.4% | May 25, 2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Split... |
| CVE-2026-9451 | MEDIUM | 6.3 | 0.2% | May 25, 2026 | A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unk... |
| CVE-2026-9450 | MEDIUM | 6.3 | 0.2% | May 25, 2026 | A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of ... |
| CVE-2026-9449 | MEDIUM | 6.3 | 0.2% | May 25, 2026 | A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the ... |
| CVE-2026-9448 | MEDIUM | 4.3 | 0.3% | May 25, 2026 | A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown function of the ... |
| CVE-2026-46745 | MEDIUM | 5.3 | 0.6% | May 25, 2026 | Apache Airflow FAB Auth Manager contains an LDAP filter injection vulnerability (CWE-90) that allows unauthenticated att... |
| CVE-2026-40127 | MEDIUM | 5.3 | 0.3% | May 25, 2026 | OutSystems Lifetime is vulnerable to Authorization Bypass Through User-Controlled Key vulnerability in ApplicationID par... |
| CVE-2026-9446 | MEDIUM | 4.7 | 0.3% | May 25, 2026 | A vulnerability has been found in SourceCodester Simple POS and Inventory System 1.0. The affected element is an unknown... |
| CVE-2026-9445 | MEDIUM | 6.3 | 0.3% | May 25, 2026 | A flaw has been found in SourceCodester Simple POS and Inventory System 1.0. Impacted is an unknown function of the file... |
| CVE-2026-9444 | MEDIUM | 4.7 | 0.3% | May 25, 2026 | A vulnerability was detected in SourceCodester Simple POS and Inventory System 1.0. This issue affects the function dele... |
| CVE-2026-9441 | MEDIUM | 6.3 | 1.4% | May 25, 2026 | A security flaw has been discovered in Edimax BR-6478AC 1.23. Affected by this issue is the function formiNICbasic of th... |
| CVE-2026-9274 | MEDIUM | 5.2 | 0.1% | May 25, 2026 | This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory.... |
| CVE-2026-5223 | MEDIUM | 5.3 | 0.3% | May 25, 2026 | Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious... |
| CVE-2026-5222 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. I... |
| CVE-2026-9490 | MEDIUM | 5.5 | 0.2% | May 25, 2026 | A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a we... |
| CVE-2026-9440 | MEDIUM | 6.3 | 1.4% | May 25, 2026 | A vulnerability was identified in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formAccept of th... |
| CVE-2026-9439 | MEDIUM | 6.3 | 1.2% | May 25, 2026 | A vulnerability was determined in Edimax BR-6675nD 1.12. Affected is the function stainfo of the file /goform/stainfo. T... |
| CVE-2026-9438 | MEDIUM | 5.4 | 0.3% | May 25, 2026 | A vulnerability was found in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This imp... |
| CVE-2026-9437 | MEDIUM | 6.3 | 1.4% | May 25, 2026 | A vulnerability has been found in DTStack Taier 1.4.0. This affects the function Runtime.exec of the component REST API.... |
| CVE-2026-4915 | MEDIUM | 6.5 | 0.3% | May 25, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil element... |
| CVE-2026-45249 | MEDIUM | 6.1 | 0.8% | May 25, 2026 | A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. Thi... |
| CVE-2026-41863 | MEDIUM | 6.5 | 0.4% | May 25, 2026 | Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing ... |
| CVE-2026-9424 | MEDIUM | 6.3 | 1.2% | May 25, 2026 | A weakness has been identified in Edimax EW-7438RPn 1.31. The affected element is the function formWlanMP of the file /g... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now