2026 CVE Vulnerabilities
48,325 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40094 | MEDIUM | 4.3 | 0.3% | May 20, 2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network... |
| CVE-2026-39960 | MEDIUM | 5.4 | 0.2% | May 20, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that cause... |
| CVE-2026-9136 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlle... |
| CVE-2026-9124 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacke... |
| CVE-2026-9122 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentiall... |
| CVE-2026-9116 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker t... |
| CVE-2026-9115 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker ... |
| CVE-2026-9113 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of... |
| CVE-2026-9110 | MEDIUM | 4.2 | 0.3% | May 20, 2026 | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had... |
| CVE-2026-47099 | MEDIUM | 6.1 | 0.4% | May 20, 2026 | TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows atta... |
| CVE-2026-39311 | MEDIUM | 6.8 | 0.3% | May 20, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
| CVE-2026-35016 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authen... |
| CVE-2026-35015 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows ... |
| CVE-2026-35014 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows aut... |
| CVE-2026-35013 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows a... |
| CVE-2026-35012 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows a... |
| CVE-2026-35011 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authent... |
| CVE-2026-35010 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows au... |
| CVE-2026-35009 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows auth... |
| CVE-2026-35008 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authen... |
| CVE-2026-35007 | MEDIUM | 5.1 | 0.2% | May 20, 2026 | Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows a... |
| CVE-2026-2813 | MEDIUM | 4.1 | 0.3% | May 20, 2026 | ArcGIS Server contains an input validation weakness in the login redirection workflow. An Authenticated attacker could e... |
| CVE-2026-2812 | MEDIUM | 5.3 | 0.4% | May 20, 2026 | ArcGIS Server contains an improper authentication vulnerability in an undocumented administrative endpoint. An unauthent... |
| CVE-2026-26028 | MEDIUM | 6.1 | 0.2% | May 20, 2026 | CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Dif... |
| CVE-2026-30691 | MEDIUM | 6.1 | 0.3% | May 20, 2026 | Cross-Site Scripting (XSS) vulnerability in @cyntler/react-doc-viewer v1.17.1 allows remote attackers to execute arbitra... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now