2026 CVE Vulnerabilities
48,301 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39593 | MEDIUM | 6.5 | 0.3% | May 21, 2026 | Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security... |
| CVE-2026-48213 | MEDIUM | 5.4 | 0.2% | May 21, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authentic... |
| CVE-2026-36189 | MEDIUM | 6.2 | 0.1% | May 21, 2026 | Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e... |
| CVE-2026-1816 | MEDIUM | 6.3 | 0.2% | May 21, 2026 | Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation ... |
| CVE-2026-1815 | MEDIUM | 5.7 | 0.2% | May 21, 2026 | Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application... |
| CVE-2026-34926 | MEDIUM | 6.7 | 12.7% | May 21, 2026 | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker t... |
| CVE-2026-6841 | MEDIUM | 6.1 | 0.2% | May 21, 2026 | Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET re... |
| CVE-2026-43496 | MEDIUM | 5.5 | 0.1% | May 21, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_red: Replace direct dequeue call wit... |
| CVE-2026-0393 | MEDIUM | 6.5 | 0.2% | May 21, 2026 | The affected product may expose credentials remotely between low privileged visualization users during concurrent login ... |
| CVE-2026-45254 | MEDIUM | 6.5 | 0.2% | May 21, 2026 | In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key ... |
| CVE-2026-45252 | MEDIUM | 5.5 | 0.3% | May 21, 2026 | When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace ... |
| CVE-2026-42396 | MEDIUM | 6.5 | 0.4% | May 21, 2026 | Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail |
| CVE-2026-41999 | MEDIUM | 4.8 | 0.1% | May 21, 2026 | Incorrect Behaviour of Views with TCP PROXY Requests |
| CVE-2026-5434 | MEDIUM | 5.9 | 0.2% | May 21, 2026 | Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An atta... |
| CVE-2026-27393 | MEDIUM | 5.3 | 0.2% | May 21, 2026 | Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2026-27349 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint all... |
| CVE-2026-22880 | MEDIUM | 6.1 | 0.1% | May 21, 2026 | Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO aut... |
| CVE-2026-4055 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when crea... |
| CVE-2026-44076 | MEDIUM | 6.7 | 0.1% | May 21, 2026 | Insufficient sanitization of volume paths in Netatalk 3.1.0 through 4.4.2 allows a local privileged user to inject OS co... |
| CVE-2026-44073 | MEDIUM | 5 | 0.3% | May 21, 2026 | Authentication modules in Netatalk 1.5.0 through 4.4.2 fail to check the return value of seteuid(), which may allow a re... |
| CVE-2026-44067 | MEDIUM | 4.2 | 0.3% | May 21, 2026 | A heap over-read in extended attribute (EA) header parsing in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated... |
| CVE-2026-44065 | MEDIUM | 4.2 | 0.1% | May 21, 2026 | An off-by-two error in lp_write() in papd in Netatalk 2.0.0 through 4.4.2 allows an adjacent network attacker to modify ... |
| CVE-2026-44063 | MEDIUM | 4.2 | 0.2% | May 21, 2026 | An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDA... |
| CVE-2026-44061 | MEDIUM | 5.9 | 0.4% | May 21, 2026 | Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker ... |
| CVE-2026-44059 | MEDIUM | 4.5 | 0.1% | May 21, 2026 | A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain lim... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now