2026 CVE Vulnerabilities
48,325 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20240 | MEDIUM | 6.5 | 0.4% | May 20, 2026 | In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.11, and 9.3.12, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-20239 | MEDIUM | 6.5 | 0.5% | May 20, 2026 | In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.1... |
| CVE-2026-20238 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could a... |
| CVE-2026-9101 | MEDIUM | 5.3 | 0.4% | May 20, 2026 | Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering she... |
| CVE-2026-9100 | MEDIUM | 6 | 0.3% | May 20, 2026 | The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. ... |
| CVE-2026-44924 | MEDIUM | 5.4 | 0.2% | May 20, 2026 | InfoScale VIOM 9.1.3 allows XSS. |
| CVE-2026-44923 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | SQL injection in InfoScale VIOM before v9.1.3 allows remote attackers to escalate privileges. |
| CVE-2026-20206 | MEDIUM | 6.3 | 0.4% | May 20, 2026 | A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, ... |
| CVE-2026-20171 | MEDIUM | 6.8 | 0.5% | May 20, 2026 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switc... |
| CVE-2026-9084 | MEDIUM | 6 | 0.2% | May 20, 2026 | MISP’s OIDC authentication plugin allowed automatic linking of an OIDC identity to an existing local user account based ... |
| CVE-2026-4293 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | The affected Kieback & Peter DDC building controllers are vulnerable to cross-site scripting, enabling JavaScript to be ... |
| CVE-2026-21836 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, documen... |
| CVE-2026-5950 | MEDIUM | 5.3 | 0.6% | May 20, 2026 | An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling ... |
| CVE-2026-5947 | MEDIUM | 5.9 | 1.4% | May 20, 2026 | Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incomi... |
| CVE-2026-45443 | MEDIUM | 5 | 0.2% | May 20, 2026 | Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Explo... |
| CVE-2026-3592 | MEDIUM | 5.3 | 0.4% | May 20, 2026 | BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a quer... |
| CVE-2026-27424 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Missing Authorization vulnerability in WP Chill Image Photo Gallery Final Tiles Grid allows Exploiting Incorrectly Confi... |
| CVE-2026-27405 | MEDIUM | 6.5 | 0.3% | May 20, 2026 | Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2026-24573 | MEDIUM | 6.5 | 0.2% | May 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Visualiz... |
| CVE-2026-25602 | MEDIUM | 4.4 | 0.1% | May 20, 2026 | Insufficient Verification of Data Authenticity vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona S... |
| CVE-2026-0857 | MEDIUM | 6 | 0.1% | May 20, 2026 | Cleartext Storage of Sensitive Information in Memory vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo M... |
| CVE-2026-6728 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ... |
| CVE-2026-44608 | MEDIUM | 5.9 | 0.3% | May 20, 2026 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain... |
| CVE-2026-44390 | MEDIUM | 5.3 | 0.6% | May 20, 2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets t... |
| CVE-2026-42923 | MEDIUM | 5.3 | 0.3% | May 20, 2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now