2026 CVE Vulnerabilities
48,516 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8096 | MEDIUM | 6.5 | 0.4% | May 19, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa... |
| CVE-2026-34154 | MEDIUM | 5.3 | 0.2% | May 19, 2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1... |
| CVE-2026-33741 | MEDIUM | 6.8 | 0.2% | May 19, 2026 | EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use... |
| CVE-2026-33637 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 ... |
| CVE-2026-32738 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequen... |
| CVE-2026-32134 | MEDIUM | 5.9 | 0.4% | May 19, 2026 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles... |
| CVE-2026-36827 | MEDIUM | 5.4 | 0.7% | May 19, 2026 | A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface inv... |
| CVE-2026-8706 | MEDIUM | 6.5 | 0.2% | May 19, 2026 | Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same devi... |
| CVE-2026-45557 | MEDIUM | 6.9 | 0.4% | May 19, 2026 | Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in con... |
| CVE-2026-34883 | MEDIUM | 5.3 | 0.1% | May 19, 2026 | An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a ... |
| CVE-2026-8971 | MEDIUM | 6.5 | 0.2% | May 19, 2026 | Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird ... |
| CVE-2026-8961 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderb... |
| CVE-2026-8951 | MEDIUM | 6.5 | 0.3% | May 19, 2026 | Spoofing issue in the Toolbar component in Firefox for Android. This vulnerability was fixed in Firefox 151. |
| CVE-2026-23557 | MEDIUM | 6.5 | 0.2% | May 19, 2026 | Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri... |
| CVE-2026-4630 | MEDIUM | 6.8 | 0.3% | May 19, 2026 | A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerabi... |
| CVE-2026-45442 | MEDIUM | 4.3 | 0.2% | May 19, 2026 | Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Co... |
| CVE-2026-43492 | MEDIUM | 5.5 | 0.2% | May 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_... |
| CVE-2026-43491 | MEDIUM | 5.5 | 0.1% | May 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registratio... |
| CVE-2026-37982 | MEDIUM | 6.8 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsAction... |
| CVE-2026-37981 | MEDIUM | 4.3 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows... |
| CVE-2026-37979 | MEDIUM | 6.5 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection ... |
| CVE-2026-37978 | MEDIUM | 4.9 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking th... |
| CVE-2026-46724 | MEDIUM | 5.9 | 0.4% | May 19, 2026 | The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer config... |
| CVE-2026-46723 | MEDIUM | 5.9 | 0.3% | May 19, 2026 | The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backe... |
| CVE-2026-46722 | MEDIUM | 5.9 | 0.3% | May 19, 2026 | The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document place... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now