2026 CVE Vulnerabilities
48,516 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5293 | MEDIUM | 6.4 | 0.3% | May 20, 2026 | The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js'... |
| CVE-2026-43620 | MEDIUM | 5.5 | 0.5% | May 20, 2026 | Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver... |
| CVE-2026-43617 | MEDIUM | 6.3 | 0.3% | May 20, 2026 | Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access ... |
| CVE-2026-45585 | MEDIUM | 6.8 | 1.2% | May 20, 2026 | Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". ... |
| CVE-2026-39309 | MEDIUM | 5.5 | 0.2% | May 20, 2026 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas... |
| CVE-2026-35593 | MEDIUM | 6.8 | 0.6% | May 20, 2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled... |
| CVE-2026-34970 | MEDIUM | 5.3 | 0.4% | May 20, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to acces... |
| CVE-2026-34754 | MEDIUM | 4.3 | 0.2% | May 20, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to ... |
| CVE-2026-8493 | MEDIUM | 5.4 | 0.2% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox In... |
| CVE-2026-6871 | MEDIUM | 6.1 | 0.2% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate a... |
| CVE-2026-6367 | MEDIUM | 6.1 | 0.2% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core... |
| CVE-2026-6366 | MEDIUM | 6.6 | 0.4% | May 19, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow... |
| CVE-2026-6365 | MEDIUM | 6.1 | 0.2% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core... |
| CVE-2026-6095 | MEDIUM | 6.1 | 0.2% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Orejime all... |
| CVE-2026-34744 | MEDIUM | 5.3 | 0.4% | May 19, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and downl... |
| CVE-2026-34600 | MEDIUM | 5.7 | 0.3% | May 19, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions 3.5.2... |
| CVE-2026-34579 | MEDIUM | 5.3 | 0.4% | May 19, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization... |
| CVE-2026-5090 | MEDIUM | 6.1 | 0.3% | May 19, 2026 | Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter funct... |
| CVE-2026-34390 | MEDIUM | 5.1 | 0.4% | May 19, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vul... |
| CVE-2026-34246 | MEDIUM | 4.8 | 0.2% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc... |
| CVE-2026-34233 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers... |
| CVE-2026-34216 | MEDIUM | 6.6 | 0.5% | May 19, 2026 | CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update ... |
| CVE-2026-32814 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid imag... |
| CVE-2026-42526 | MEDIUM | 5.3 | 0.4% | May 19, 2026 | In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0... |
| CVE-2026-32739 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now