2026 CVE Vulnerabilities
48,306 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44065 | MEDIUM | 4.2 | 0.1% | May 21, 2026 | An off-by-two error in lp_write() in papd in Netatalk 2.0.0 through 4.4.2 allows an adjacent network attacker to modify ... |
| CVE-2026-44063 | MEDIUM | 4.2 | 0.2% | May 21, 2026 | An LDAP injection vulnerability in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to manipulate LDA... |
| CVE-2026-44061 | MEDIUM | 5.9 | 0.4% | May 21, 2026 | Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker ... |
| CVE-2026-44059 | MEDIUM | 4.5 | 0.1% | May 21, 2026 | A race condition in the privilege toggle mechanism in Netatalk 2.2.5 through 4.4.2 allows a local attacker to obtain lim... |
| CVE-2026-44056 | MEDIUM | 6.4 | 0.3% | May 21, 2026 | A stack-based buffer overflow in desktop.c in Netatalk 1.3 through 4.2.2 allows a remote authenticated attacker to cause... |
| CVE-2026-44054 | MEDIUM | 6.5 | 0.3% | May 21, 2026 | Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs, which allows a remote au... |
| CVE-2026-2734 | MEDIUM | 6.5 | 0.4% | May 21, 2026 | In mlflow/mlflow versions up to 3.9.0, the `SearchModelVersions` REST API endpoint and the `mlflowSearchModelVersions` G... |
| CVE-2026-1543 | MEDIUM | 6.4 | 0.3% | May 21, 2026 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcodes in ... |
| CVE-2026-4811 | MEDIUM | 4.9 | 0.3% | May 21, 2026 | The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to Sto... |
| CVE-2026-1881 | MEDIUM | 4.3 | 0.2% | May 21, 2026 | The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includ... |
| CVE-2026-9149 | MEDIUM | 6.5 | 0.3% | May 21, 2026 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted ... |
| CVE-2026-9150 | MEDIUM | 6.5 | 0.4% | May 20, 2026 | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser w... |
| CVE-2026-47782 | MEDIUM | 4.6 | 0.1% | May 20, 2026 | Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL v... |
| CVE-2026-40102 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-cont... |
| CVE-2026-40094 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network... |
| CVE-2026-39960 | MEDIUM | 5.4 | 0.2% | May 20, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that cause... |
| CVE-2026-9136 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlle... |
| CVE-2026-9124 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacke... |
| CVE-2026-9122 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentiall... |
| CVE-2026-9116 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker t... |
| CVE-2026-9115 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker ... |
| CVE-2026-9113 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of... |
| CVE-2026-9110 | MEDIUM | 4.2 | 0.3% | May 20, 2026 | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had... |
| CVE-2026-47099 | MEDIUM | 6.1 | 0.4% | May 20, 2026 | TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows atta... |
| CVE-2026-39311 | MEDIUM | 6.8 | 0.3% | May 20, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now