2026 CVE Vulnerabilities
48,516 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46721 | MEDIUM | 6.9 | 0.4% | May 19, 2026 | The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on th... |
| CVE-2026-45187 | MEDIUM | 6.5 | 0.5% | May 19, 2026 | Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users... |
| CVE-2026-35086 | MEDIUM | 6.5 | 0.5% | May 19, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue a... |
| CVE-2026-31906 | MEDIUM | 6.1 | 0.4% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. Thi... |
| CVE-2026-31388 | MEDIUM | 5.3 | 0.4% | May 19, 2026 | Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: bef... |
| CVE-2026-31387 | MEDIUM | 5.3 | 0.5% | May 19, 2026 | Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are rec... |
| CVE-2026-31380 | MEDIUM | 6.5 | 0.5% | May 19, 2026 | Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') v... |
| CVE-2026-31379 | MEDIUM | 6.1 | 0.6% | May 19, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname ... |
| CVE-2026-31378 | MEDIUM | 6.5 | 0.6% | May 19, 2026 | Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are r... |
| CVE-2026-29220 | MEDIUM | 6.5 | 0.7% | May 19, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issu... |
| CVE-2026-29207 | MEDIUM | 6.5 | 0.5% | May 19, 2026 | Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects... |
| CVE-2026-44408 | MEDIUM | 6.3 | 0.3% | May 19, 2026 | There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an... |
| CVE-2026-8922 | MEDIUM | 5.4 | 0.3% | May 19, 2026 | A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Key... |
| CVE-2026-8830 | MEDIUM | 4.3 | 0.4% | May 19, 2026 | A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registrati... |
| CVE-2026-8814 | MEDIUM | 5.5 | 0.5% | May 19, 2026 | Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amp... |
| CVE-2026-32994 | MEDIUM | 5.3 | 0.3% | May 19, 2026 | The /api/v1/autotranslate.translateMessage endpoint in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.6, <7.13.8,... |
| CVE-2026-28733 | MEDIUM | 6.5 | 0.1% | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution. |
| CVE-2026-27766 | MEDIUM | 5.5 | 0.1% | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak. |
| CVE-2026-25850 | MEDIUM | 5.5 | 0.1% | May 19, 2026 | in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak |
| CVE-2026-33514 | MEDIUM | 4.3 | 0.3% | May 19, 2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1... |
| CVE-2026-33234 | MEDIUM | 5 | 0.3% | May 19, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-33052 | MEDIUM | 5.3 | 0.3% | May 19, 2026 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authent... |
| CVE-2026-32312 | MEDIUM | 4.3 | 0.2% | May 19, 2026 | GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with f... |
| CVE-2026-32244 | MEDIUM | 5.3 | 0.2% | May 19, 2026 | Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1... |
| CVE-2026-27892 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now