2026 CVE Vulnerabilities
48,516 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27737 | MEDIUM | 6.5 | 0.3% | May 18, 2026 | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation for... |
| CVE-2026-47091 | MEDIUM | 4.8 | 0.1% | May 18, 2026 | Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to r... |
| CVE-2026-47090 | MEDIUM | 4.6 | 0.1% | May 18, 2026 | Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd... |
| CVE-2026-45246 | MEDIUM | 6.8 | 0.1% | May 18, 2026 | Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite p... |
| CVE-2026-45244 | MEDIUM | 5.4 | 0.2% | May 18, 2026 | Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automa... |
| CVE-2026-21789 | MEDIUM | 4.6 | 0.1% | May 18, 2026 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai... |
| CVE-2026-45243 | MEDIUM | 6.1 | 0.2% | May 18, 2026 | Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge... |
| CVE-2026-45231 | MEDIUM | 6.1 | 0.2% | May 18, 2026 | DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, descripti... |
| CVE-2026-45494 | MEDIUM | 6.1 | 0.3% | May 18, 2026 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2026-45492 | MEDIUM | 5.4 | 0.3% | May 18, 2026 | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security featur... |
| CVE-2026-32849 | MEDIUM | 5.7 | 0.1% | May 18, 2026 | NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/op... |
| CVE-2026-32848 | MEDIUM | 5.7 | 0.1% | May 18, 2026 | NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem... |
| CVE-2026-29965 | MEDIUM | 6.1 | 0.2% | May 18, 2026 | HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to ... |
| CVE-2026-29964 | MEDIUM | 6.1 | 0.2% | May 18, 2026 | HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to impro... |
| CVE-2026-38719 | MEDIUM | 6.2 | 0.1% | May 18, 2026 | OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specific... |
| CVE-2026-36438 | MEDIUM | 5.3 | 0.3% | May 18, 2026 | An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information ... |
| CVE-2026-20685 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addres... |
| CVE-2026-8803 | MEDIUM | 6.3 | 0.2% | May 18, 2026 | A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file... |
| CVE-2026-8802 | MEDIUM | 5.3 | 0.4% | May 18, 2026 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function get... |
| CVE-2026-41119 | MEDIUM | 6.8 | 0.1% | May 18, 2026 | Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A rem... |
| CVE-2026-6345 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user pass... |
| CVE-2026-6343 | MEDIUM | 4.3 | 0.2% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions whi... |
| CVE-2026-6339 | MEDIUM | 4.3 | 0.1% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read ... |
| CVE-2026-6333 | MEDIUM | 5 | 0.1% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response UR... |
| CVE-2026-5163 | MEDIUM | 6.5 | 0.2% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites whic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now