2026 CVE Vulnerabilities
48,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40610 | MEDIUM | 5.5 | 0.3% | May 22, 2026 | BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1... |
| CVE-2026-40598 | MEDIUM | 6.9 | 0.4% | May 22, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the re... |
| CVE-2026-40295 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module... |
| CVE-2026-39969 | MEDIUM | 6.5 | 0.1% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/works... |
| CVE-2026-39966 | MEDIUM | 6.5 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions t... |
| CVE-2026-42627 | MEDIUM | 6.2 | 0.1% | May 22, 2026 | In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a craft... |
| CVE-2026-39964 | MEDIUM | 5.4 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor t... |
| CVE-2026-42626 | MEDIUM | 5.9 | 0.2% | May 22, 2026 | HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD... |
| CVE-2026-36227 | MEDIUM | 6.5 | 0.9% | May 22, 2026 | Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and e... |
| CVE-2026-36226 | MEDIUM | 6.1 | 0.3% | May 22, 2026 | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensit... |
| CVE-2026-28735 | MEDIUM | 5.4 | 0.1% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth... |
| CVE-2026-28444 | MEDIUM | 6.5 | 0.3% | May 22, 2026 | Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller ag... |
| CVE-2026-9251 | MEDIUM | 5.4 | 0.1% | May 22, 2026 | Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authentica... |
| CVE-2026-9246 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated... |
| CVE-2026-9245 | MEDIUM | 5 | 0.2% | May 22, 2026 | Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated r... |
| CVE-2026-9224 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory ... |
| CVE-2026-9223 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged... |
| CVE-2026-5171 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Improper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access... |
| CVE-2026-42506 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ... |
| CVE-2026-42502 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ... |
| CVE-2026-27136 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ... |
| CVE-2026-25681 | MEDIUM | 6.1 | 0.2% | May 22, 2026 | Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged ... |
| CVE-2026-25680 | MEDIUM | 6.5 | 0.2% | May 22, 2026 | Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. |
| CVE-2026-8353 | MEDIUM | 4.8 | 0.1% | May 22, 2026 | Concrete CMS version 9.0 to 9.5.0 is vulnerable to Stored XSS via page name in the Atomik theme. A rogue editor can inje... |
| CVE-2026-8347 | MEDIUM | 4.3 | 0.2% | May 22, 2026 | Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now